Database/Control plane, storage & DevOps
Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.js: Unauthenticated arbitrary file deletion
Impact
Unauthenticated arbitrary file deletion on the IPM server. Less glamorous than the RCEs but operationally pointed: an attacker can delete the configuration and driver files that let IPM talk to your UPS estate, silently disabling the power-response layer without triggering anything that looks like an attack.
Who can reach it
Unauthenticated, remote, to the IPM server.
What to do
Upgrade to IPM 1.69 or later. Also verify you have restorable backups of IPM configuration - the recovery path for this bug is restore, and most operators have never tested it.
References
Related entries
- Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated userCVE-2022-21225 · Intel Data Center ManagerHigh
- Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwordsCVE-2022-32519 · Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storageHigh
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorCVE-2024-39368 · Intel Neural Compressor (SQL injection)High
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesCVE-2024-45766 · Dell OpenManage Enterprise (code injection)High
- Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silentlyCVE-2025-68803 · Linux NFS server (nfsd, NFSv4 file creation ACL)High
- Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesCVE-2025-7766 · Lantronix Provisioning ManagerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.