ZeroHour

CVE-2021-23276

CVSS 3.1
8.8 high
EPSS
<1%p54
Published
()
Modified
Description

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.

Vendors
eaton
Products
intelligent power manager, intelligent power manager virtual appliance, intelligent power protector
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.