File parsing Type Confusion Remote code execution vulerability
Vulnerability Description
Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The vulnerability arises due to improper validation of user data supplied through E70 file which is causing Type Confusion.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-6656
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Eaton would like to thank Francis Provencher from ZDI
References
- https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/easySoft-eaton-vulnerability-advisory.pdf
- https://www.zerodayinitiative.com/advisories/ZDI-20-1441/
- https://www.zerodayinitiative.com/advisories/ZDI-20-1442/
- https://www.zerodayinitiative.com/advisories/ZDI-20-1444/
- https://us-cert.cisa.gov/ics/advisories/icsa-21-007-03
More from Eaton
View All →Affected Vendor
Eaton
View all reports →