PT-2021-12500 · Eaton · Easysoft
Francis Provencher
·
Published
2021-01-07
·
Updated
2021-03-31
·
CVE-2020-6655
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Eaton's easySoft software versions 7.0 through 7.21
Description:
The issue arises due to improper validation and parsing of the .E70 file content by the application, allowing a malicious entity to execute malicious code or crash the application by tricking a user into uploading a malformed .E70 file.
Recommendations:
For versions 7.0 through 7.21, update to version 7.22 or later to resolve the issue. As a temporary workaround, consider restricting the upload of .E70 files or validating their content before processing to minimize the risk of exploitation.
Fix
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easysoft