Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-27799 Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.
Fixes

Solution

Upgrade to the latest version 1.68 available on eaton.com


Workaround

Remove users which are not part of the origination and having accounts in the software. Block port 4679 & 4680 at enterprise network firewall to prevent malicious users from accessing the software outside the facility.

History

Tue, 17 Sep 2024 00:00:00 +0000

Type Values Removed Values Added
Title Incorrect privilege assignment allowing non-admin users to upload config files Incorrect privilege assignment allowing non-admin users to upload config files

cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published:

Updated: 2024-09-16T23:45:31.152Z

Reserved: 2020-01-09T00:00:00

Link: CVE-2020-6652

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-07T16:15:11.390

Modified: 2024-11-21T05:36:06.013

Link: CVE-2020-6652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.