PT-2020-19206 · Eaton · Eaton Intelligent Power Manager
Zebasquared
·
Published
2020-05-07
·
Updated
2020-05-12
·
CVE-2020-6652
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eaton Intelligent Power Manager versions 1.67 and prior
Description
The issue allows non-admin users to upload system configuration files by sending specially crafted requests, potentially resulting in non-admin users manipulating system configurations via uploading configurations with incorrect parameters.
Recommendations
For versions 1.67 and prior, consider restricting access to the system configuration upload feature to prevent non-admin users from manipulating system configurations until a patch is available.
As a temporary workaround, limit the ability of non-admin users to send specially crafted requests to the system.
Restrict access to system configuration files to minimize the risk of exploitation.
Fix
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eaton Intelligent Power Manager