Database/Firmware, BMC & network fabric

Tripp Lite PDUMH15AT / SU750XL PDU: The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which can
Impact
The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which can be used to change the manager or admin password, or directly shut off power to an outlet. Anyone who can reach the PDU's web interface can cut power to whatever rack that outlet feeds, with no login at all.
Who can reach it
Fully remote and unauthenticated — a crafted POST request to the /Forms/ directory is all that's needed to flip an outlet or take over the admin account.
What to do
Software/firmware upgrade — Tripp Lite (now Eaton) shipped a fixed release after this was reported; confirm every deployed unit is past 12.04.0053 (PDUMH15AT) / 12.04.0052 (SU750XL). Flash each PDU; this directly powers a rack, so schedule around a window where a brief power-monitoring interruption is acceptable, and audit for units still on vulnerable firmware since these are frequently forgotten 'fringe' infrastructure.
References
Related entries
- IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCVE-2019-4169 · IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handlingCritical
- Lanner IAC-AST2500A BMC firmware: An authenticated BMC user escalates to root code execution on the controllerCVE-2021-26731 · Lanner IAC-AST2500A BMC firmwareCritical
- Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switchCVE-2021-28506 · Arista EOS (gNOI)Critical
- APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signing: Firmware images are signed with a key that leakedCVE-2022-0715 · APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signingCritical
- AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subvertedCVE-2023-28863 · AMI MegaRAC SPx12/SPx13Critical
- CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection throughCVE-2023-3267 · CyberPower PowerPanel Enterprise DCIM - remote backup location username fieldCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.