Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Eaton
Published: 2020-05-07T15:58:21.660327Z
Updated: 2024-09-16T23:06:52.876Z
Reserved: 2020-01-09T00:00:00
Link: CVE-2020-6651
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-07T16:15:11.313
Modified: 2024-11-21T05:36:05.900
Link: CVE-2020-6651
Redhat
No data.