Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-27799 | Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters. |
Fixes
Solution
Upgrade to the latest version 1.68 available on eaton.com
Workaround
Remove users which are not part of the origination and having accounts in the software. Block port 4679 & 4680 at enterprise network firewall to prevent malicious users from accessing the software outside the facility.
References
History
Tue, 17 Sep 2024 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Incorrect privilege assignment allowing non-admin users to upload config files | Incorrect privilege assignment allowing non-admin users to upload config files |

Status: PUBLISHED
Assigner: Eaton
Published:
Updated: 2024-09-16T23:45:31.152Z
Reserved: 2020-01-09T00:00:00
Link: CVE-2020-6652

No data.

Status : Modified
Published: 2020-05-07T16:15:11.390
Modified: 2024-11-21T05:36:06.013
Link: CVE-2020-6652

No data.

No data.