CVE-2020-6656
File parsing Type Confusion Remote code execution vulerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The vulnerability arises due to improper validation of user data supplied through E70 file which is causing Type Confusion.
El software easySoft de Eaton versiones v7.xx y anteriores a la v7.22 es susceptible a la vulnerabilidad de ejecución remota de código por confusión de tipo de archivo. Una entidad maliciosa puede ejecutar un código malicioso o hacer que la aplicación se bloquee engañando al usuario para que cargue un archivo .E70 malformado en la aplicación. La vulnerabilidad surge debido a la incorrecta validación de los datos del usuario suministrados a través del archivo E70, lo que provoca una confusión de tipos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-09 CVE Reserved
- 2021-01-07 CVE Published
- 2024-08-04 CVE Updated
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-007-03 | Third Party Advisory | |
https://www.zerodayinitiative.com/advisories/ZDI-20-1441 | Third Party Advisory | |
https://www.zerodayinitiative.com/advisories/ZDI-20-1442 | Third Party Advisory | |
https://www.zerodayinitiative.com/advisories/ZDI-20-1444 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eaton Search vendor "Eaton" | Easysoft Search vendor "Eaton" for product "Easysoft" | >= 7.00 < 7.20 Search vendor "Eaton" for product "Easysoft" and version " >= 7.00 < 7.20" | - |
Affected
|