CVE-2021-23279 is a critical unauthenticated arbitrary file deletion vulnerability affecting Eaton Intelligent Power Manager (IPM) versions prior to 1.69, as well as Intelligent Power Manager Virtual Appliance and Intelligent Power Protector. This flaw, rated with a CVSS score of 10.0, allows an unauthenticated attacker to remotely delete files on affected systems by sending specially crafted packets due to improper input validation. While the vulnerability is severe, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.69CPE matchmatch criteria | cpe:2.3:a:eaton:intelligent_power_manager:*:*:*:*:*:*:*:* | ||
< 1.69CPE matchmatch criteria | cpe:2.3:a:eaton:intelligent_power_manager_virtual_appliance:*:*:*:*:*:*:*:* | ||
< 1.68CPE matchmatch criteria | cpe:2.3:a:eaton:intelligent_power_protector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.