Database/Control plane, storage & DevOps
Intel Data Center Manager SDK (reference UI): The DCM SDK's reference UI allows an unauthenticated remote attacker
CVSS 9.6CVE-2018-3679Control plane, storage & DevOpscurated
Impact
The DCM SDK's reference UI allows an unauthenticated remote attacker to execute code with administrator privileges. Reference UIs get shipped into production more often than vendors expect - if you built anything on the DCM SDK, check whether the sample UI went with it.
Who can reach it
Unauthenticated remote attacker able to reach the reference UI.
What to do
Upgrade the DCM SDK past 5.0 and remove the reference UI from any production deployment. Application-level change; no host reboot or firmware.
References
Related entries
- BeeGFS (beegfs-ctl / metadata server): Authentication bypass by talking directly to a BeeGFS metadata server. BeeGFS isCVE-2019-15897 · BeeGFS (beegfs-ctl / metadata server)Critical
- Dell OpenManage Enterprise (remote code execution): Remote code execution on the OpenManage Enterprise consoleCVE-2021-21596 · Dell OpenManage Enterprise (remote code execution)Critical
- Tailscale (Windows client): Local API bound to a TCP socketCVE-2022-41924 · Tailscale (Windows client)Critical
- GitLab: Attacker can trigger a CI pipeline as another userCVE-2024-6385 · GitLabCritical
- AAP Controller: testing a Vault credential sends the controller pod's service account token to an attacker URLCVE-2026-12564 · Red Hat Ansible Automation Platform Controller (awx_plugins HashiCorp Vault credential plugin)Critical
- Termix: any authenticated user can read other users' stored SSH and sudo passwordsCVE-2026-53548 · Termix (GET /host/db/host/:id/password credential endpoint)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.