PT-2022-21875 · Eaton · Eaton Foreseer Epms
Michael
·
Published
2022-10-28
·
Updated
2023-10-18
·
CVE-2022-33859
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eaton Foreseer EPMS versions 4.x through 7.5
Description
A security issue was discovered in the Eaton Foreseer EPMS software, which connects devices to reduce energy consumption and prevent unplanned downtime. The problem allows a threat actor to upload arbitrary files using the file upload feature.
Recommendations
For versions 7.0 through 7.5, update the software to the latest version (v7.6).
For versions 4.x, 5.x, and 6.x, refer to the End-of-Support notification as these versions are no longer supported by Eaton.
As a temporary workaround for currently supported versions, consider implementing the provided mitigation until the update to version 7.6 can be applied.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eaton Foreseer Epms