Beveiligingsadvies

CVE-2021-23280

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-04-13 18:04:34
Laatst bijgewerkt 2024-09-16 17:24:07
Toegewezen door Eaton
CVSS-score 8.0
Status PUBLISHED

Beschrijving

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.