Database/Control plane, storage & DevOps
Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic eval: Unauthenticated eval injection: user-controlled
CVSS 8.3CVE-2021-23277Control plane, storage & DevOpscurated
Impact
Unauthenticated eval injection: user-controlled code syntax reaches a dynamic evaluation path. Second unauthenticated route to code execution on the same power-management server, from the same advisory batch - which is the point worth taking away. Patching one CVE in this batch and not the rest leaves the door open.
Who can reach it
Unauthenticated, remote, to the IPM server.
What to do
Upgrade to IPM 1.69 or later - the whole CVE-2021-23276 through -23281 batch lands in one release, so treat it as a single action.
References
Related entries
- Intel C++ Compiler Classic / oneAPI toolkits (Unicode source handling): Improper handling of Unicode bidirectionalCVE-2022-25987 · Intel C++ Compiler Classic / oneAPI toolkits (Unicode source handling)High
- Intel oneAPI DPC++/C++ compiler (homoglyph rendering): Homoglyph characters are not visually distinguishedCVE-2022-26843 · Intel oneAPI DPC++/C++ compiler (homoglyph rendering)High
- Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authenticationCVE-2025-0052 · Pure Storage FlashBlade authentication input validationHigh
- Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack bufferCVE-2025-26336 · Dell Chassis Management Controller (PowerEdge FX2 / VRTX)High
- VMware Avi Load Balancer: authorization bypass exposes part of the Avi Controller control planeCVE-2026-47866 · VMware Avi Load Balancer (Avi Controller control plane)High
- Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodesCVE-2026-54100 · Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.