PT-2020-19206 · Eaton · Eaton Intelligent Power Manager

Zebasquared

·

Published

2020-05-07

·

Updated

2020-05-12

·

CVE-2020-6652

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eaton Intelligent Power Manager versions 1.67 and prior
Description The issue allows non-admin users to upload system configuration files by sending specially crafted requests, potentially resulting in non-admin users manipulating system configurations via uploading configurations with incorrect parameters.
Recommendations For versions 1.67 and prior, consider restricting access to the system configuration upload feature to prevent non-admin users from manipulating system configurations until a patch is available. As a temporary workaround, limit the ability of non-admin users to send specially crafted requests to the system. Restrict access to system configuration files to minimize the risk of exploitation.

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6652
ZDI-20-650

Affected Products

Eaton Intelligent Power Manager