Description
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.
Published: 2020-05-07
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to the latest version 1.68 available on eaton.com


Vendor Workaround

Remove users which are not part of the origination and having accounts in the software. Block port 4679 & 4680 at enterprise network firewall to prevent malicious users from accessing the software outside the facility.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-27799 Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.
History

Tue, 17 Sep 2024 00:00:00 +0000

Type Values Removed Values Added
Title Incorrect privilege assignment allowing non-admin users to upload config files Incorrect privilege assignment allowing non-admin users to upload config files

Subscriptions

Eaton Intelligent Power Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published:

Updated: 2024-09-16T23:45:31.152Z

Reserved: 2020-01-09T00:00:00.000Z

Link: CVE-2020-6652

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-07T16:15:11.390

Modified: 2024-11-21T05:36:06.013

Link: CVE-2020-6652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses