Vulnerability Description
Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eaton | Intelligent Power Manager | <= 1.67 |
Related Weaknesses (CWE)
References
- https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/secuVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-650/
- https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/secuVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-650/
FAQ
What is CVE-2020-6652?
CVE-2020-6652 is a vulnerability with a CVSS score of 7.8 (HIGH). Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted reques...
How severe is CVE-2020-6652?
CVE-2020-6652 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6652?
Check the references section above for vendor advisories and patch information. Affected products include: Eaton Intelligent Power Manager.