VendorsEatonintelligent_power_managerall versions
Vulnerabilities

Eaton Intelligent Power Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2021-23279
Arbitrary File delete
Published 2021-04-13 · Modified
10.0EPSS 0.271
CVE-2021-23281
Remote Code execution
Published 2021-04-13 · Modified
10.0EPSS 0.022
CVE-2021-23277
Improper Neutralization of Directives in Dynamically Evaluated Code
Published 2021-04-13 · Modified
10.0EPSS 0.010
CVE-2021-23280
Arbitrary File upload
Published 2021-04-13 · Modified
9.9EPSS 0.009
CVE-2018-12031
Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.
Published 2018-06-07 · Modified
9.8EPSS 0.198
CVE-2021-23278
Arbitrary File delete
Published 2021-04-13 · Modified
9.6EPSS 0.010
CVE-2020-6651
Command injection via specially crafted file name during config file upload
Published 2020-05-07 · Modified
8.8EPSS 0.021
CVE-2021-23276
Improper Neutralization of Special Elements used in an SQL Command
Published 2021-04-13 · Modified
8.8EPSS 0.008
CVE-2021-23286
Security issues in Eaton Intelligent Power Manager Infrastructure
Published 2022-04-18 · Modified
8.0EPSS 0.004
CVE-2020-6652
Incorrect privilege assignment allowing non-admin users to upload config files
Published 2020-05-07 · Modified
7.8EPSS 0.004
CVE-2021-23287
Security issues in Intelligent Power Manager (IPM 1)
Published 2022-04-01 · Modified
5.6EPSS 0.005
CVE-2021-23285
Security issues in Eaton Intelligent Power Manager Infrastructure
Published 2022-04-18 · Modified
4.8EPSS 0.004