CVE Published: 07/05/2020 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: Eaton |
Vendor: Eaton |
Product: Intelligent Power manager (IPM) Status : PUBLISHED
CVE-2020-6651 Description
Improper Input Validation in Eaton\'s Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H