CVE-2021-23288
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
01/04/2022
Last modified:
09/04/2022
Description
The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. This issue affects: Intelligent Power Protector versions prior to 1.69.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Base Score 2.0
2.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:eaton:intelligent_power_protector:*:*:*:*:*:*:*:* | 1.69 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



