Aller au contenu

Fiche vulnérabilité

CVE-2021-23279 : faille critique eaton intelligent power manager (CVSS 10.0)

Description

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID. An attacker can send specially crafted packets to delete the files on the system where IPM software is installed.

En bref

Sévérité
Critique (CVSS 10.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 avr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • eaton intelligent power manager
  • eaton intelligent power manager virtual appliance
  • eaton intelligent power protector

Références

Rechercher une autre vulnérabilité dans la base CVE