HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2020-6650

CVSS 8.3v3.1pub. 2020-03-23upd. 2024-11-21

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.

CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Eaton Ups Companion

    APP
    Eaton
    ≤ 1.05
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-59887HIGH8.6same product

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary...

CVE-2025-67450HIGH7.8same product

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the...

CVE-2025-59888MEDIUM6.7same product

Nieprawidłowe cytowanie w ścieżkach wyszukiwania w instalatorze oprogramowania Eaton UPS Companion może prowad...

CVE-2021-23281CRITICAL10.0PL ✓same vendor

Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP

CVE-2018-16158CRITICAL9.8PL ✓same vendor

Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root