Database/Firmware, BMC & network fabric
Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directory
Impact
Local file inclusion through directory traversal on the firmware parameter of the node upgrade service. The affected code path is the one that distributes firmware to managed power devices, so this is an attacker standing in the middle of your UPS firmware supply chain.
Who can reach it
Remote to the IPM server, unauthenticated per the advisory.
What to do
Upgrade IPM well past 1.6 - anything on 1.6 is also carrying the 2020 and 2021 unauthenticated RCEs. Gate firmware distribution to power devices behind change control regardless of the platform you use.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.