ZeroHour

CVE-2021-23279

CVSS 3.1
10.0 critical
EPSS
27%p98
Published
()
Modified
Description

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID. An attacker can send specially crafted packets to delete the files on the system where IPM software is installed.

Vendors
eaton
Products
intelligent power manager, intelligent power manager virtual appliance, intelligent power protector
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.