5.6
CVE-2021-23288
- EPSS 0.07%
- Veröffentlicht 01.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:30
- Quelle CybersecurityCOE@eaton.com
- CVE-Watchlists
- Unerledigt
The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. This issue affects: Intelligent Power Protector versions prior to 1.69.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eaton ≫ Intelligent Power Protector Version < 1.69
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.207 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 2.3 | 4.4 | 2.9 |
AV:A/AC:M/Au:S/C:N/I:P/A:N
|
| CybersecurityCOE@eaton.com | 5.6 | 0.4 | 5.2 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.