Description
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
No analysis available yet.
Remediation
Vendor Solution
Update the software to latest version 1.68.
Vendor Workaround
Block ports 4679 & 4680 at enterprise network or home network where Intelligent Power Manager (IPM) software is installed and used.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-27798 | Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application. |
References
History
No history.
Status: PUBLISHED
Assigner: Eaton
Published:
Updated: 2024-09-16T23:06:52.876Z
Reserved: 2020-01-09T00:00:00.000Z
Link: CVE-2020-6651
No data.
Status : Modified
Published: 2020-05-07T16:15:11.313
Modified: 2024-11-21T05:36:05.900
Link: CVE-2020-6651
No data.
OpenCVE Enrichment
No data.
EUVD