Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6656

Опубликовано: 07 янв. 2021
Источник: nvd
CVSS3: 5.8
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The vulnerability arises due to improper validation of user data supplied through E70 file which is causing Type Confusion.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eaton:easysoft:*:*:*:*:*:*:*:*
Версия от 7.00 (включая) до 7.20 (исключая)

EPSS

Процентиль: 74%
0.00799
Низкий

5.8 Medium

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-20
CWE-843

Связанные уязвимости

github
больше 3 лет назад

Eaton's easySoft software v7.20 and prior are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The vulnerability arises due to improper validation of user data supplied through E70 file which is causing Type Confusion.

EPSS

Процентиль: 74%
0.00799
Низкий

5.8 Medium

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-20
CWE-843