CVE-2022-33859
Unrestricted file upload in Eaton Foreseer EPMS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file upload feature.
This vulnerability is present in versions 4.x, 5.x, 6.x & 7.0 to 7.5. A new version (v7.6) containing the remediation has been made available by Eaton and a mitigation has been provided for the affected versions that are currently supported.
Customers are advised to update the software to the latest version (v7.6).
Foreseer EPMS versions 4.x, 5.x, 6.x are no longer supported by Eaton. Please refer to the End-of-Support notification https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html .
Se descubrió una vulnerabilidad de seguridad en el software Eaton Foreseer EPMS. Foreseer EPMS conecta la amplia gama de dispositivos de una operación para ayudar a reducir el consumo de energía y evitar tiempos de inactividad no planificados causados ??por fallas de sistemas críticos. Un actor de amenazas puede cargar archivos arbitrarios utilizando la función de carga de archivos. Esta vulnerabilidad está presente en las versiones 4.x, 5.x, 6.x y 7.0 a 7.5. Eaton puso a disposición una nueva versión (v7.6) que contiene la solución y se proporcionó una mitigación para las versiones afectadas que son compatibles actualmente. Se recomienda a los clientes que actualicen el software a la última versión (v7.6). Eaton ya no admite las versiones 4.x, 5.x y 6.x de Foreseer EPMS. Consulte la notificación de fin de soporte https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-15 CVE Reserved
- 2022-10-28 CVE Published
- 2024-05-20 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.eaton.com/us/en-us/company/news-insights/cybersecurity/security-notifications.html | 2023-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eaton Search vendor "Eaton" | Foreseer Electrical Power Monitoring System Search vendor "Eaton" for product "Foreseer Electrical Power Monitoring System" | >= 4.0 < 7.6 Search vendor "Eaton" for product "Foreseer Electrical Power Monitoring System" and version " >= 4.0 < 7.6" | - |
Affected
|