Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.
oryginał ENCVSS Vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HEaton Intelligent Power Manager
APPEaton< 1.69Eaton Intelligent Power Manager Virtual Appliance
APPEaton< 1.69Eaton Intelligent Power Protector
APPEaton< 1.68
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
SQLi
Powiązane podatności
CVE-2021-23281CRITICAL10.0PL ✓ten sam produkt
Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP
CVE-2018-12031CRITICAL9.8PL ✓ten sam produkt
Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6
CVE-2026-22619HIGH7.8ten sam produkt
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could...
CVE-2021-23279HIGH8.0ten sam produkt
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vul...
CVE-2021-23278HIGH8.7ten sam produkt
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulne...