ZeroHour

CVE-2020-6651

CVSS 3.1
7.3 high
EPSS
2%p81
Published
()
Modified
Description

Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.

Vendors
eaton
Products
intelligent power manager
Weakness
CWE-20, CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.