CVE-2020-6655

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
07/01/2021
Last modified:
31/03/2021

Description

The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed .E70 file in the application. The vulnerability arises due to improper validation and parsing of the E70 file content by the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eaton:easysoft:*:*:*:*:*:*:*:* 7.00 (including) 7.22 (excluding)