Arbitrary file upload in Eaton products - CVE-2021-23280
Published: April 21, 2021
Vulnerability identifier: #VU52456
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23280
CWE-ID: CWE-434
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the "uploadBackground" function in "maps_srv.js". A remote authenticated attacker on the local network can upload a malicious file and execute it on the server.
Affected software
Intelligent Power Protector
Intelligent Power Manager
Intelligent Power Manager Virtual Appliance
Intelligent Power Manager
Intelligent Power Manager Virtual Appliance
How to mitigate CVE-2021-23280
Install update from vendor's website.
Intelligent Power Protector - update to 1.68
Intelligent Power Manager - update to 1.69
Intelligent Power Manager Virtual Appliance - update to 1.69
Intelligent Power Manager - update to 1.69
Intelligent Power Manager Virtual Appliance - update to 1.69