CVE-2022-33859
Last modified
CVE-2022-33859 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file upload feature. This vulnerability is present in versions 4.x, 5.x, 6.x & 7.0 to 7.5. A new version (v7.6) containing the remediation has been made available by Eaton and a mitigation has been provided for the affected versions that are currently supported. Customers are advised to update the software to the latest version (v7.6). Foreseer EPMS versions 4.x, 5.x, 6.x are no longer supported by Eaton. Please refer to the End-of-Support notification https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html .
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eaton | Foreseer Electrical Power Monitoring System | >= 4.0, < 7.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-33859?
How severe is CVE-2022-33859?
How do I fix CVE-2022-33859?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-3380The Customizer Export/Import WordPress plugin before 0.9.5 u…7.2
- CVE-2022-3381An issue has been discovered in GitLab affecting all version…6.1
- CVE-2022-3382HIWIN Robot System Software version 3.3.21.9869 does not pro…7.5
- CVE-2022-3383The Ultimate Member plugin for WordPress is vulnerable to Re…7.2
- CVE-2022-3384The Ultimate Member plugin for WordPress is vulnerable to Re…7.2
- CVE-2022-3385 Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable…9.8
- CVE-2022-3386 Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable…9.8
- CVE-2022-33860Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. Co…
- CVE-2022-33861IPP software versions prior to v1.71 do not sufficiently ver…5.1
- CVE-2022-33862IPP software prior to v1.71 is vulnerable to default credent…6.7
- CVE-2022-33869An improper neutralization of special elements used in an OS…8.8
- CVE-2022-3387 Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable…5.3
Are you affected by CVE-2022-33859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
