Input validation error in Intelligent Power Manager - CVE-2020-6651

 

Input validation error in Intelligent Power Manager - CVE-2020-6651

Published: May 13, 2020


Vulnerability identifier: #VU27871
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-6651
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system

The vulnerability exists due to the affected software does not validate the import configuration file names properly within "system_srv.js". A remote authenticated attacker can send specially crafted file names while uploading the config file in the application and execute arbitrary code on the target system.


Affected software

Intelligent Power Manager

How to mitigate CVE-2020-6651

Install updates from vendor's website.

Intelligent Power Manager - update to 1.68

External References

Related Security Bulletins