Database/Control plane, storage & DevOps
Eaton Intelligent Power Manager (IPM) prior to 1.69: PHYSICAL. Unauthenticated remote code execution on Eaton's
Impact
PHYSICAL. Unauthenticated remote code execution on Eaton's power-management platform, via unsanitised data reaching a Node.js code path. IPM is the software that monitors and shuts down infrastructure in response to power events across a site, so unauthenticated RCE here is total control of the power-response layer. A CVSS 10.0 on facility software is rare and this one earns it.
Who can reach it
Unauthenticated, remote, over the network to the IPM server.
What to do
Upgrade IPM to 1.69 or later. Server-side upgrade, so cheap in maintenance terms - but assume compromise on any instance that was network-reachable and rebuild rather than patch. Rotate every device credential IPM held. IPM ships as part of several OEM power bundles, so check for it under other names before concluding you do not run it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.