You are here

Eaton Intelligent Power Manager (ICSA-20-133-01) – Product Used in Energy Sector

Eaton Intelligent Power Manager (ICSA-20-133-01) – Product Used in Energy Sector

Created: Wednesday, May 13, 2020 - 13:04
Categories:
Cybersecurity

CISA has published an advisory on improper input validation and incorrect privilege assignment vulnerabilities in Eaton Intelligent Power Manager. Versions 1.67 and prior are affected. Successful exploitation of these vulnerabilities could allow an attacker to perform command injection or code execution and allow non-administrator users to manipulate the system configurations. Eaton has released Intelligent Power Manager v1.68 to address the reported vulnerabilities. CISA also recommends a series of measures to mitigate the vulnerabilities. Read the advisory at CISA.