CVE-2020-10637: Eaton Hmisoft VU3 Firmware

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could trigger an out-of-bounds read when loaded by the affected product.

Affected products

  • Eaton Hmisoft VU3 Firmware: up to and including 3.00.23

Published 2020-04-15. Last modified 2026-06-17.