#VU52452 Input validation error in Eaton products - CVE-2021-23278
Published: April 21, 2021
Intelligent Power Manager
Intelligent Power Manager Virtual Appliance
Intelligent Power Protector
Eaton
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the "removeBackground" function in "server/maps_srv.js" and "removeFirmware" function in "server/node_upgrade_srv.js". A remote authenticated attacker on the local network can send specially crafted packets to delete the files on the system where IPM software is installed.