HIGH✓ PATCH🇬🇧 English

CVE-2020-6650

CVSS 8.3v3.1pub. 2020-03-23upd. 2024-11-21

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.

oryginał EN
CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Eaton Ups Companion

    APP
    Eaton
    ≤ 1.05
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
RCE
CWE
Referencje

Powiązane podatności

CVE-2025-59887HIGH8.6ten sam produkt

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary...

CVE-2025-67450HIGH7.8ten sam produkt

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the...

CVE-2025-59888MEDIUM6.7ten sam produkt

Nieprawidłowe cytowanie w ścieżkach wyszukiwania w instalatorze oprogramowania Eaton UPS Companion może prowad...

CVE-2021-23281CRITICAL10.0PL ✓ten sam vendor

Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP

CVE-2018-16158CRITICAL9.8PL ✓ten sam vendor

Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root