Eaton.IPM.meta_driver_srv.Arbitrary.File.Deletion

description-logoDescription

This indicates an attack attempt to exploit an Arbitrary File Deletion Vulnerability in Eaton Intelligent Power Protector.
The vulnerability is due to missing input validation in meta_driver_srv.js. A remote unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted packet. Successful exploitation of these vulnerabilities could allow attackers to delete arbitrary files on the target system.

affected-products-logoAffected Products

Eaton Intelligent Power Manager 1.69 and prior
Eaton Intelligent Power Protector 1.68 and prior

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

References

ICSA-21-110-06