PT-2022-9392 · Eaton · Eaton Intelligent Power Manager Infrastructure

Published

2022-04-18

·

Updated

2022-04-27

·

CVE-2021-23286

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) versions 1.5.0plus205 and prior versions.
Description The issue is related to CSV Formula Injection. This affects all versions of Eaton Intelligent Power Manager Infrastructure prior to and including version 1.5.0plus205.
Recommendations For versions 1.5.0plus205 and prior, update to a version that is not affected by this issue, as all versions prior to and including 1.5.0plus205 are vulnerable.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23286

Affected Products

Eaton Intelligent Power Manager Infrastructure