PT-2021-12500 · Eaton · Easysoft

Francis Provencher

·

Published

2021-01-07

·

Updated

2021-03-31

·

CVE-2020-6655

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Eaton's easySoft software versions 7.0 through 7.21
Description: The issue arises due to improper validation and parsing of the .E70 file content by the application, allowing a malicious entity to execute malicious code or crash the application by tricking a user into uploading a malformed .E70 file.
Recommendations: For versions 7.0 through 7.21, update to version 7.22 or later to resolve the issue. As a temporary workaround, consider restricting the upload of .E70 files or validating their content before processing to minimize the risk of exploitation.

Fix

Out of bounds Read

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6655

Affected Products

Easysoft