Database/Firmware, BMC & network fabric
Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directory
Impact
Local file inclusion through directory traversal on the firmware parameter of the node upgrade service. The affected code path is the one that distributes firmware to managed power devices, so this is an attacker standing in the middle of your UPS firmware supply chain.
Who can reach it
Remote to the IPM server, unauthenticated per the advisory.
What to do
Upgrade IPM well past 1.6 - anything on 1.6 is also carrying the 2020 and 2021 unauthenticated RCEs. Gate firmware distribution to power devices behind change control regardless of the platform you use.
References
Related entries
- Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCVE-2018-1207 · Dell iDRAC7/8Critical
- Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems): An unprivilegedCVE-2018-12171 · Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems)Critical
- QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenter: Three undocumentedCVE-2018-18202 · QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenterCritical
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web serverCVE-2018-7243 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabledCVE-2018-7246 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentialsCVE-2018-7820 · APC UPS Network Management Card 2 (AOS 6.5.6)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.