PT-2021-12501 · Eaton · Easysoft
Francis Provencher
·
Published
2021-01-07
·
Updated
2021-03-31
·
CVE-2020-6656
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Eaton's easySoft software versions 7.00 through 7.20
Description:
The issue arises due to improper validation of user data supplied through .E70 files, causing Type Confusion. A malicious entity can execute malicious code or make the application crash by tricking a user into uploading a malformed .E70 file.
Recommendations:
For versions 7.00 through 7.20, update to version 7.22 or later to resolve the issue.
As a temporary workaround, consider restricting the upload of .E70 files to trusted sources until a patch is available.
Fix
Type Confusion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easysoft