Database/Control plane, storage & DevOps
Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.js: Unauthenticated arbitrary file deletion
Impact
Unauthenticated arbitrary file deletion on the IPM server. Less glamorous than the RCEs but operationally pointed: an attacker can delete the configuration and driver files that let IPM talk to your UPS estate, silently disabling the power-response layer without triggering anything that looks like an attack.
Who can reach it
Unauthenticated, remote, to the IPM server.
What to do
Upgrade to IPM 1.69 or later. Also verify you have restorable backups of IPM configuration - the recovery path for this bug is restore, and most operators have never tested it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.