« Volver al listado

Eaton

Eaton UPS Companion: vulnerabilidades y CVE

Eaton UPS Companion tiene 4 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses3
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-67450Alta (7.8)0.15%—26 dic 2025
Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest…
CVE-2025-59888Media (6.7)0.19%—26 dic 2025
Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest…
CVE-2025-59887Alta (8.6)0.26%—26 dic 2025
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in…
CVE-2020-6650Alta (8.8)2.1%—23 mar 2020
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval”…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1574.007 Path Interception by PATH Environment Variable2
  2. T1068 Exploitation for Privilege Escalation1
  3. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Eaton