Database/Control plane, storage & DevOps
Altair PBS Professional / OpenPBS (pbs_mom): Pbs_mom, the daemon that executes jobs on every compute node, accepts
Impact
Pbs_mom, the daemon that executes jobs on every compute node, accepts messages without authenticating them. Send it a message directly and you get code execution on that node with the daemon's privileges - which is how a tenant on one node reaches into the execution path of jobs belonging to everyone else on the cluster.
Who can reach it
Adjacent network - anything that can open a socket to pbs_mom on a compute node. On a flat cluster network that is every tenant with a running job.
What to do
Upgrade past PBS Professional 19.1.2 / the corresponding OpenPBS release. Until then, firewall the pbs_mom port so that only the pbs_server host can reach it - the daemon has no business accepting connections from compute peers. Rolling the pbs_mom binary requires draining each node.
References
Related entries
- Ceph MON / MGR (ceph-mon, ceph-mgr): Ceph-mon and ceph-mgr fail to enforce the caps on an authenticated principal, so aCVE-2020-10736 · Ceph MON / MGR (ceph-mon, ceph-mgr)High
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.js: Unauthenticated arbitrary file deletionCVE-2021-23279 · Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.jsHigh
- Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated userCVE-2022-21225 · Intel Data Center ManagerHigh
- Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwordsCVE-2022-32519 · Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storageHigh
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorCVE-2024-39368 · Intel Neural Compressor (SQL injection)High
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesCVE-2024-45766 · Dell OpenManage Enterprise (code injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.