PT-2021-12501 · Eaton · Easysoft

Francis Provencher

·

Published

2021-01-07

·

Updated

2021-03-31

·

CVE-2020-6656

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Eaton's easySoft software versions 7.00 through 7.20
Description: The issue arises due to improper validation of user data supplied through .E70 files, causing Type Confusion. A malicious entity can execute malicious code or make the application crash by tricking a user into uploading a malformed .E70 file.
Recommendations: For versions 7.00 through 7.20, update to version 7.22 or later to resolve the issue. As a temporary workaround, consider restricting the upload of .E70 files to trusted sources until a patch is available.

Fix

Type Confusion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6656

Affected Products

Easysoft