// For flags

CVE-2022-33859

Unrestricted file upload in Eaton Foreseer EPMS

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file upload feature.

This vulnerability is present in versions 4.x, 5.x, 6.x & 7.0 to 7.5. A new version (v7.6) containing the remediation has been made available by Eaton and a mitigation has been provided for the affected versions that are currently supported.

Customers are advised to update the software to the latest version (v7.6).

Foreseer EPMS versions 4.x, 5.x, 6.x are no longer supported by Eaton. Please refer to the End-of-Support notification https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html .

Se descubrió una vulnerabilidad de seguridad en el software Eaton Foreseer EPMS. Foreseer EPMS conecta la amplia gama de dispositivos de una operación para ayudar a reducir el consumo de energía y evitar tiempos de inactividad no planificados causados ??por fallas de sistemas críticos. Un actor de amenazas puede cargar archivos arbitrarios utilizando la función de carga de archivos. Esta vulnerabilidad está presente en las versiones 4.x, 5.x, 6.x y 7.0 a 7.5. Eaton puso a disposición una nueva versión (v7.6) que contiene la solución y se proporcionó una mitigación para las versiones afectadas que son compatibles actualmente. Se recomienda a los clientes que actualicen el software a la última versión (v7.6). Eaton ya no admite las versiones 4.x, 5.x y 6.x de Foreseer EPMS. Consulte la notificación de fin de soporte https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html.

*Credits: Michael
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-06-15 CVE Reserved
  • 2022-10-28 CVE Published
  • 2024-05-20 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eaton
Search vendor "Eaton"
Foreseer Electrical Power Monitoring System
Search vendor "Eaton" for product "Foreseer Electrical Power Monitoring System"
>= 4.0 < 7.6
Search vendor "Eaton" for product "Foreseer Electrical Power Monitoring System" and version " >= 4.0 < 7.6"
-
Affected