PT-2022-21875 · Eaton · Eaton Foreseer Epms

Michael

·

Published

2022-10-28

·

Updated

2023-10-18

·

CVE-2022-33859

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eaton Foreseer EPMS versions 4.x through 7.5
Description A security issue was discovered in the Eaton Foreseer EPMS software, which connects devices to reduce energy consumption and prevent unplanned downtime. The problem allows a threat actor to upload arbitrary files using the file upload feature.
Recommendations For versions 7.0 through 7.5, update the software to the latest version (v7.6). For versions 4.x, 5.x, and 6.x, refer to the End-of-Support notification as these versions are no longer supported by Eaton. As a temporary workaround for currently supported versions, consider implementing the provided mitigation until the update to version 7.6 can be applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-33859

Affected Products

Eaton Foreseer Epms