HIGH
File parsing Out-Of-Bounds read remote code execution
Published Jan 7, 2021
7.8
HIGHCVSS 3.1
EPSS 2.77%
Description
The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed .E70 file in the application. The vulnerability arises due to improper validation and parsing of the E70 file content by the application.
Affected products
-
- Version v7.xx prior to v7.22StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Eaton | easySoft Software | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Apply the patch once it is provided by Eaton.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27802 Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-007-03 x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/easySoft-eaton-vulnerability-advisory.pdf x_refsource_MISCVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1443/ x_refsource_MISCThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27802 | Advisory | |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-007-03 | x_refsource_MISCThird Party AdvisoryUS Government Resource | |
| https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/easySoft-eaton-vulnerability-advisory.pdf | x_refsource_MISCVendor Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1443/ | x_refsource_MISCThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Eaton
Published Jan 7, 2021
Updated Aug 4, 2024
Reserved Jan 9, 2020
Link CVE-2020-6655
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-27802 Assigner Eaton
Published Jan 7, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-27802