CVE-2020-10639: Eaton Hmisoft VU3 Firmware

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could cause a buffer overflow when loaded by the affected product.

Affected products

  • Eaton Hmisoft VU3 Firmware: up to and including 3.00.23

Published 2020-04-15. Last modified 2026-06-17.