Description
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
Published: 2020-05-07
Score: 8.8 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update the software to latest version 1.68.


Vendor Workaround

Block ports 4679 & 4680 at enterprise network or home network where Intelligent Power Manager (IPM) software is installed and used.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-27798 Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
History

No history.

Subscriptions

Eaton Intelligent Power Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published:

Updated: 2024-09-16T23:06:52.876Z

Reserved: 2020-01-09T00:00:00.000Z

Link: CVE-2020-6651

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-07T16:15:11.313

Modified: 2024-11-21T05:36:05.900

Link: CVE-2020-6651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses