Database/Control plane, storage & DevOps
Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra service: Unauthenticated remote code execution
Impact
Unauthenticated remote code execution on a central plant controller. The enteliBUS Manager is the box that sequences chillers, pumps, boilers and air handling for a whole building; the research that produced this bug demonstrated full control over HVAC and, on the same hardware family, over the access-control and life-safety points wired into it. Owning it gives an attacker root-equivalent control over the mechanical plant with no credentials and no user interaction, plus the ability to lie to the supervisory system above it. Against a GPU hall this is the textbook scenario: command the plant off or drive setpoints, and a 40 kW+ rack crosses thermal shutdown in minutes while the BMS graphic still shows normal operation. Because the compromise is code execution rather than a config change, it also persists across reboots and survives the operator's instinctive 'restart the controller' response.
Who can reach it
Unauthenticated network access to the controller's service port on the facility network - no credentials, no interaction. enteliBUS controllers are commonly reachable from anywhere on the building VLAN and, in sites where the controls contractor set up remote support, from the internet through a poorly-placed remote-access appliance.
What to do
Firmware update from Delta Controls, applied through the certified Delta dealer who owns the site - operators generally cannot obtain or apply Delta firmware directly, which is itself the problem. That means a scheduled contractor visit and a plant controller offline during the flash: real cooling risk, real cost, and a window most operators will not take without an incident to justify it. Treat segmentation as the primary control: dedicated VLAN, deny-by-default with an allow-list from the supervisor only, and no path from the internet. Verify by scanning your own facility VLAN for the controller's service port rather than trusting the dealer's assurance.
References
Related entries
- Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.gCVE-2020-12812 · Fortinet FortiOS SSL-VPNCritical
- Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remoteCVE-2020-15373 · Brocade Fabric OS REST APICritical
- Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same consoleCVE-2020-15639 · Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management)Critical
- Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem duringCVE-2020-36770 · Slurm (Gentoo ebuild pkg_postinst)Critical
- Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as rootCVE-2021-1361 · Cisco Nexus 3000/9000 (internal file management service)Critical
- GitLab: unauthenticated SSRF through webhooks reaches the internal networkCVE-2021-22175 · GitLab (webhook request handling)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.