CVE-2018-12031

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
07/06/2018
Last modified:
27/07/2018

Description

Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eaton:intelligent_power_manager:1.6:*:*:*:*:*:*:*