Security Advisory

CVE-2021-23280

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-04-13 18:04:34
Last updated 2024-09-16 17:24:07
Assigner Eaton
State PUBLISHED

Description

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.