Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-27798 | Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application. |
Fixes
Solution
Update the software to latest version 1.68.
Workaround
Block ports 4679 & 4680 at enterprise network or home network where Intelligent Power Manager (IPM) software is installed and used.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Eaton
Published:
Updated: 2024-09-16T23:06:52.876Z
Reserved: 2020-01-09T00:00:00
Link: CVE-2020-6651
No data.
Status : Modified
Published: 2020-05-07T16:15:11.313
Modified: 2024-11-21T05:36:05.900
Link: CVE-2020-6651
No data.
OpenCVE Enrichment
No data.
EUVD