Eaton Intelligent Power Manager (IPM) w wersjach przed 1.69 jest podatny na nieuwierzytelniony remote code execution. Atakujący zdalnie, bez żadnych uprawnień, może wykonać dowolny kod na systemie ofiary.
▸ Pokaż oryginał (EN)
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to make IPM connect to rouge SNMP server and execute attacker-controlled code.
Oprogramowanie IPM nie filtruje danych dostarczanych przez akcję coverterCheckList w klasie meta_driver_srv.js. Atakujący wysyła specjalnie spreparowany pakiet, który powoduje, że IPM nawiązuje połączenie z kontrolowanym przez napastnika, fałszywym serwerem SNMP. Za pośrednictwem tego połączenia możliwe jest wykonanie dowolnego kodu sterowanego przez atakującego.
Atakujący może przejąć pełną kontrolę nad systemem, na którym działa IPM – uzyskując możliwość odczytu i modyfikacji danych oraz zakłócenia dostępności usługi. Ze względu na brak wymogu uwierzytelnienia i zasięg sieciowy podatność stanowi krytyczne zagrożenie dla infrastruktury zasilania.
Należy zaktualizować Eaton Intelligent Power Manager do wersji 1.69 lub nowszej. Szczegółowe informacje dostępne są w biuletynie bezpieczeństwa producenta pod adresem wskazanym w referencjach.
Eaton Intelligent Power Manager (IPM) w wersjach wcześniejszych niż 1.69
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HEaton Intelligent Power Manager
APPEaton< 1.69
Powiązane podatności
Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulne...
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious ...
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerabil...
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vul...