HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-23276

CVSS 7.1v3.1pub. 2021-04-13upd. 2024-11-21

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.

CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Eaton Intelligent Power Manager

    APP
    Eaton
    < 1.69
  • Eaton Intelligent Power Manager Virtual Appliance

    APP
    Eaton
    < 1.69
  • Eaton Intelligent Power Protector

    APP
    Eaton
    < 1.68
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2021-23281CRITICAL10.0PL ✓same product

Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP

CVE-2018-12031CRITICAL9.8PL ✓same product

Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6

CVE-2026-22619HIGH7.8same product

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could...

CVE-2021-23279HIGH8.0same product

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vul...

CVE-2021-23278HIGH8.7same product

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulne...