VYPR
Unrated severityNVD Advisory· Published May 7, 2020· Updated Sep 16, 2024

Command injection via specially crafted file name during config file upload

CVE-2020-6651

Description

Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file in the application.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.