{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T22:05:52.631","vulnerabilities":[{"cve":{"id":"CVE-2022-33859","sourceIdentifier":"CybersecurityCOE@eaton.com","published":"2022-10-28T02:15:17.343","lastModified":"2026-06-17T04:49:23.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file upload feature. \n\nThis vulnerability is present in versions 4.x, 5.x, 6.x & 7.0 to 7.5. A new version (v7.6) containing the remediation has been made available by Eaton and a mitigation has been provided for the affected versions that are currently supported. \n\nCustomers are advised to update the software to the latest version (v7.6).\n\nForeseer EPMS versions 4.x, 5.x, 6.x are no longer supported by Eaton. Please refer to the  End-of-Support notification https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html ."},{"lang":"es","value":"Se descubrió una vulnerabilidad de seguridad en el software Eaton Foreseer EPMS. Foreseer EPMS conecta la amplia gama de dispositivos de una operación para ayudar a reducir el consumo de energía y evitar tiempos de inactividad no planificados causados ??por fallas de sistemas críticos. Un actor de amenazas puede cargar archivos arbitrarios utilizando la función de carga de archivos. Esta vulnerabilidad está presente en las versiones 4.x, 5.x, 6.x y 7.0 a 7.5. Eaton puso a disposición una nueva versión (v7.6) que contiene la solución y se proporcionó una mitigación para las versiones afectadas que son compatibles actualmente. Se recomienda a los clientes que actualicen el software a la última versión (v7.6). Eaton ya no admite las versiones 4.x, 5.x y 6.x de Foreseer EPMS. Consulte la notificación de fin de soporte https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html."}],"affected":[{"source":"CybersecurityCOE@eaton.com","affectedData":[{"vendor":"Eaton","product":"Foreseer EPMS","defaultStatus":"unaffected","versions":[{"version":"7.0","status":"affected"},{"version":"4.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"CybersecurityCOE@eaton.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.5,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-06T19:40:16.330230Z","id":"CVE-2022-33859","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"CybersecurityCOE@eaton.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:eaton:foreseer_electrical_power_monitoring_system:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndExcluding":"7.6","matchCriteriaId":"DC1A434B-BDB3-44CF-8FB8-2DFD7F1C3DE9"}]}]}],"references":[{"url":"https://www.eaton.com/us/en-us/company/news-insights/cybersecurity/security-notifications.html","source":"CybersecurityCOE@eaton.com","tags":["Vendor Advisory"]},{"url":"https://www.eaton.com/us/en-us/company/news-insights/cybersecurity/security-notifications.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}