GPU VulnDB

Database/Firmware, BMC & network fabric

Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directory

CVE-2018-12031Firmware, BMC & network fabriccurated

Impact

Local file inclusion through directory traversal on the firmware parameter of the node upgrade service. The affected code path is the one that distributes firmware to managed power devices, so this is an attacker standing in the middle of your UPS firmware supply chain.

Who can reach it

Remote to the IPM server, unauthenticated per the advisory.

What to do

Upgrade IPM well past 1.6 - anything on 1.6 is also carrying the 2020 and 2021 unauthenticated RCEs. Gate firmware distribution to power devices behind change control regardless of the platform you use.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.