ID:5634 - Exploit for Path traversal in Intelligent Power Manager - CVE-2018-12031

 
Main Vulnerability Database Exploits ID:5634 - Exploit for Path traversal in Intelligent Power Manager - CVE-2018-12031

ID:5634 - Exploit for Path traversal in Intelligent Power Manager - CVE-2018-12031

Published: June 17, 2021


Vulnerability identifier: #VU37069
Vulnerability risk: High
CVE-ID: CVE-2018-12031
CWE-ID: CWE-22
Exploitation vector: Remote access
Vulnerable software:
Intelligent Power Manager

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.


Remediation

Install update from vendor's website.