GPU VulnDB

Database/Control plane, storage & DevOps

Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic eval: Unauthenticated eval injection: user-controlled

CVE-2021-23277Control plane, storage & DevOpscurated

Impact

Unauthenticated eval injection: user-controlled code syntax reaches a dynamic evaluation path. Second unauthenticated route to code execution on the same power-management server, from the same advisory batch - which is the point worth taking away. Patching one CVE in this batch and not the rest leaves the door open.

Who can reach it

Unauthenticated, remote, to the IPM server.

What to do

Upgrade to IPM 1.69 or later - the whole CVE-2021-23276 through -23281 batch lands in one release, so treat it as a single action.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.