PT-2021-15431 · Eaton · Eaton Intelligent Power Manager
Amir Preminger
·
Published
2021-04-13
·
Updated
2021-04-21
·
CVE-2021-23278
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eaton Intelligent Power Manager (IPM) versions prior to 1.69
Description
The issue is related to improper input validation, allowing an authenticated arbitrary file delete vulnerability. This vulnerability can be exploited by sending specially crafted packets to delete files on the system where the IPM software is installed. The vulnerability is specifically induced at
server/maps srv.js with the action removeBackground and at server/node upgrade srv.js with the action removeFirmware.Recommendations
For versions prior to 1.69, update to version 1.69 or later to resolve the issue. As a temporary workaround, consider restricting access to the
server/maps srv.js and server/node upgrade srv.js files to minimize the risk of exploitation. Additionally, avoid using the removeBackground and removeFirmware actions in the affected API endpoints until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eaton Intelligent Power Manager