Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:HEaton Ups Companion
APPEaton< 3.0
Related vulnerabilities
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary...
Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the...
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neut...
Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP
Eaton Power Xpert Meter — zakodowany klucz SSH umożliwia logowanie jako root