CVE-2020-6651 HIGH

CVE-2020-6651: Command injection via specially crafted file name during config file upload

Vendor Eaton
Product Intelligent Power manager (IPM)
Weakness CWE-20 · Input validation
Published May 7, 2020
Last update September 16, 2024

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.

Key dates

02Disclosure timeline

May 7, 2020 CVE published
September 16, 2024 Record updated