← Vulnerability feed

Vulnerability record · CVE-2020-6650 · published 23 March 2020

CVE-2020-6650: Eaton ups companion code injection vulnerability

Eaton · Ups Companion

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.

8.8 CVSS 3.1 High EPSS 2.1% · top 19.0% CWE-95 · CWE-95CWE-94 · Code injection
8.8CVSS 3.1 base score, v2 5.8
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6650 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-59887Eaton ups companion uncontrolled search path element vulnerabilityImproper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the…EPSS 0.26%7.8CVE-2025-67450Eaton ups companion uncontrolled search path element vulnerabilityDue to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitra…EPSS 0.15%6.7CVE-2025-59888Eaton ups companion unquoted search path vulnerabilityImproper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the acces…EPSS 0.19%9.3CVE-2026-33017Langflow build_public_tmp endpoint unauthenticated remote code executionLangflow versions prior to 1.9.0 expose the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint without authentication, and when the optional data …KEVEPSS 25%analysed9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.8CVE-2024-36401GeoServer OGC request parameter XPath eval injection enables unauthenticated RCEGeoServer versions before 2.22.6, 2.23.6, 2.24.4, and 2.25.2 unsafely evaluate OGC request parameters as XPath expressions via the GeoTools commons-j…KEVEPSS 100%analysed7.8CVE-2023-7101Spreadsheet::ParseExcel Perl module code injection via Excel number format stringsSpreadsheet::ParseExcel 0.65, a Perl module for parsing Excel files, passes unvalidated input from a file into a string-type eval. Specifically, Numb…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2020-6650), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.