7.5
CVSSv2

CVE-2021-23277

Published: 13/04/2021 Updated: 26/06/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Eaton Intelligent Power Manager (IPM) before 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function under scripts/libs/utils.js. Successful exploitation can allow malicious users to control the input to the function and execute attacker controlled commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eaton intelligent power manager

eaton intelligent power manager virtual appliance

eaton intelligent power protector