Fiche vulnérabilité
CVE-2020-6651 : faille élevée eaton intelligent power manager (CVSS 7.3)
Description
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.
En bref
- Sévérité
- Élevée (CVSS 7.3)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 mai 2020
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- eaton intelligent power manager