Aller au contenu

Fiche vulnérabilité

CVE-2021-23277 : faille critique eaton intelligent power manager (CVSS 10.0)

Description

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function under scripts/libs/utils.js. Successful exploitation can allow attackers to control the input to the function and execute attacker controlled commands.

En bref

Sévérité
Critique (CVSS 10.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 avr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • eaton intelligent power manager
  • eaton intelligent power manager virtual appliance
  • eaton intelligent power protector

Références

Rechercher une autre vulnérabilité dans la base CVE