Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.
CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HEaton Intelligent Power Manager
APPEaton< 1.69Eaton Intelligent Power Manager Virtual Appliance
APPEaton< 1.69Eaton Intelligent Power Protector
APPEaton< 1.68
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
Related vulnerabilities
CVE-2021-23281CRITICAL10.0PL ✓same product
Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP
CVE-2018-12031CRITICAL9.8PL ✓same product
Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6
CVE-2026-22619HIGH7.8same product
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could...
CVE-2021-23279HIGH8.0same product
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vul...
CVE-2021-23278HIGH8.7same product
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulne...