← Vulnerability feed

Vulnerability record · CVE-2021-23281 · published 13 April 2021

CVE-2021-23281: Eaton intelligent power manager code injection vulnerability

Eaton · Intelligent Power Manager

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to make IPM connect to rouge SNMP server and execute attacker-controlled code.

10.0 CVSS 3.1 Critical EPSS 2.2% · top 17.9% CWE-94 · Code injection
10.0CVSS 3.1 base score, v2 7.5
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to make IPM connect to rouge SNMP server and execute attacker-controlled code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23281 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-23277Eaton intelligent power manager code injection vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize c…EPSS 0.96%10.0CVE-2021-23279Eaton intelligent power manager improper input validation vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper inpu…EPSS 27%9.9CVE-2021-23280Eaton intelligent power manager unrestricted file upload vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an a…EPSS 0.87%9.8CVE-2018-12031Eaton intelligent power manager path traversal vulnerabilityLocal file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal …EPSS 20%9.6CVE-2021-23278Eaton intelligent power manager improper input validation vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input …EPSS 1.0%8.8CVE-2021-23276Eaton intelligent power manager sql injection vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packe…EPSS 0.79%8.0CVE-2021-23286Eaton intelligent power manager csv injection vulnerabilityEaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injecti…EPSS 0.42%7.8CVE-2020-6652Eaton intelligent power manager improper privilege management vulnerabilityIncorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system conf…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2021-23281), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.