UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HEaton Ups Companion
APPEaton≤ 1.05
Related vulnerabilities
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary...
Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the...
Nieprawidłowe cytowanie w ścieżkach wyszukiwania w instalatorze oprogramowania Eaton UPS Companion może prowad...
Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP
Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root