Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec_action.php.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Network_shutdown_module | Eaton | * | 3.1_beta (including) |
Network_shutdown_module | Eaton | 2.6 (including) | 2.6 (including) |
Network_shutdown_module | Eaton | 3.0 (including) | 3.0 (including) |
Network_shutdown_module | Eaton | 3.02 (including) | 3.02 (including) |
Network_shutdown_module | Eaton | 3.04 (including) | 3.04 (including) |