CVE-2021-23279

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID. An attacker can send specially crafted packets to delete the files on the system where IPM software is installed.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eaton:intelligent_power_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:eaton:intelligent_power_manager_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:eaton:intelligent_power_protector:*:*:*:*:*:*:*:*

Information

Published : 2021-04-13 12:15

Updated : 2021-04-21 08:06


NVD link : CVE-2021-23279

Mitre link : CVE-2021-23279


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

eaton

  • intelligent_power_manager
  • intelligent_power_protector
  • intelligent_power_manager_virtual_appliance