CVE-2020-6652

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
07/05/2020
Last modified:
12/05/2020

Description

Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system configuration files by sending specially crafted requests. This can result in non-admin users manipulating the system configurations via uploading the configurations with incorrect parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eaton:intelligent_power_manager:*:*:*:*:*:*:*:* 1.67 (including)