Eval Injection in Eaton products - CVE-2021-23277
Published: April 21, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the system.
The vulnerability exists due to the affected software does not neutralize code syntax from users before using in the dynamic evaluation call in the "loadUserFile" function under scripts/libs/utils.js. A remote attacker on the local network can control the input to the function and execute attacker-controlled commands.
Affected software
Intelligent Power Manager
Intelligent Power Manager Virtual Appliance
How to mitigate CVE-2021-23277
Intelligent Power Manager - update to 1.69
Intelligent Power Manager Virtual Appliance - update to 1.69