PT-2022-21875 · Eaton · Eaton Foreseer Epms

·

CVE-2022-33859

·

Published

2022-10-28

·

Updated

2023-10-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eaton Foreseer EPMS versions 4.x through 7.5
Description A security issue was discovered in the Eaton Foreseer EPMS software, which connects devices to reduce energy consumption and prevent unplanned downtime. The problem allows a threat actor to upload arbitrary files using the file upload feature.
Recommendations For versions 7.0 through 7.5, update the software to the latest version (v7.6). For versions 4.x, 5.x, and 6.x, refer to the End-of-Support notification as these versions are no longer supported by Eaton. As a temporary workaround for currently supported versions, consider implementing the provided mitigation until the update to version 7.6 can be applied.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33859

Affected Products

Eaton Foreseer Epms