GPU VulnDB

Database/Firmware, BMC & network fabric

Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): PHYSICAL. A backdoor root account in the PDU firmware

CVE-2020-11951Firmware, BMC & network fabriccurated

Impact

PHYSICAL. A backdoor root account in the PDU firmware. Not a weak default that an operator could change - an undocumented account shipped in the image. Anyone who knows it owns the device that switches power to the rack, and nothing in your provisioning process would ever have noticed it.

Who can reach it

Network access to the PDU management interface, with credentials that are public knowledge once the advisory is out.

What to do

Firmware update to a build that removes the account. This is a per-PDU flash, two per rack, and the update must be verified rather than assumed - check that the account is actually gone on a sample. Treat undocumented accounts as a procurement question going forward: require vendors to attest that no non-configurable accounts exist before you buy a PDU SKU at fleet scale.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.