#VU27871 Input validation error in Intelligent Power Manager


Published: 2020-05-13

Vulnerability identifier: #VU27871

Vulnerability risk: Medium

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-6651

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Intelligent Power Manager
Client/Desktop applications / Software for system administration

Vendor: Eaton

Description

The vulnerability allows a remote attacker to execute arbitrary code on the system

The vulnerability exists due to the affected software does not validate the import configuration file names properly within "system_srv.js". A remote authenticated attacker can send specially crafted file names while uploading the config file in the application and execute arbitrary code on the target system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Intelligent Power Manager: 1.67


External links
http://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/eaton-vulnerability-advisory-intelligent-power-manager-v1-1.pdf
http://www.zerodayinitiative.com/advisories/ZDI-20-649/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability