GPU VulnDB

Database/Control plane, storage & DevOps

Eaton Intelligent Power Manager (IPM) prior to 1.69: PHYSICAL. Unauthenticated remote code execution on Eaton's

CVE-2021-23281Control plane, storage & DevOpscurated

Impact

PHYSICAL. Unauthenticated remote code execution on Eaton's power-management platform, via unsanitised data reaching a Node.js code path. IPM is the software that monitors and shuts down infrastructure in response to power events across a site, so unauthenticated RCE here is total control of the power-response layer. A CVSS 10.0 on facility software is rare and this one earns it.

Who can reach it

Unauthenticated, remote, over the network to the IPM server.

What to do

Upgrade IPM to 1.69 or later. Server-side upgrade, so cheap in maintenance terms - but assume compromise on any instance that was network-reachable and rebuild rather than patch. Rotate every device credential IPM held. IPM ships as part of several OEM power bundles, so check for it under other names before concluding you do not run it.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.