Database/Firmware, BMC & network fabric

APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentials
Impact
When Remote Monitoring is turned on and then off again, the credentials used for remote monitoring stay viewable in plaintext on the card. Anyone who gets a look at the card's config (via the web UI, a config export, or a support dump) picks up a working credential to the UPS's remote-monitoring channel.
Who can reach it
Requires some access to the card's configuration or web interface (e.g. a lower-privileged account, an exported config file, or a support bundle) — not a fully unauthenticated remote exploit, but a credential-exposure path.
What to do
Credential rotation for the affected remote-monitoring account is the immediate fix; pair it with the AOS firmware update from APC that stops persisting the credential in plaintext once monitoring is disabled. Rotate credentials across the whole NMC2 fleet, not just the units you know were exposed.
References
Related entries
- Intel CSME 12.0.0-12.0.34: A buffer overflow in a CSME subsystem reachable over the network by an unauthenticatedCVE-2019-0153 · Intel CSME 12.0.0-12.0.34Critical
- Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: HeapCVE-2019-11171 · Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network servicesCritical
- Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reachCVE-2019-13553 · Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4)Critical
- Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCVE-2019-3705 · Dell iDRAC7/8Critical
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706 · Dell iDRAC9Critical
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCVE-2019-3707 · Dell iDRAC9Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.