Database/Firmware, BMC & network fabric

Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40): Arbitrary code execution on the rack PDU
Impact
Arbitrary code execution on the rack PDU. Once code runs on the PDU, an attacker has a persistent presence on the OOB network that survives every host reimage in the rack, and direct control of outlet state - so this is both a persistence problem and a PHYSICAL availability problem.
Who can reach it
Network access to the PDU management interface.
What to do
Firmware flash per PDU. Because code execution means possible implantation, a unit you believe was targeted should be re-flashed from vendor image and its stored credentials rotated, not merely updated.
References
Related entries
- OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass): The file holding IPMI account passwordsCVE-2020-14156 · OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass)High
- Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT): An attacker who gets a logged-in BMCCVE-2020-15046 · Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT)High
- ipmitool (IPMI LAN response parsing): Reverses the usual direction of BMC risk: here the management stationCVE-2020-5208 · ipmitool (IPMI LAN response parsing)High
- Cisco NX-OS / FXOS (Cisco Discovery Protocol): Root code execution on the switch from a crafted CDP frame sentCVE-2022-20824 · Cisco NX-OS / FXOS (Cisco Discovery Protocol)High
- HPE iLO 5 (adjacent-network code execution / DoS): Arbitrary code execution on the iLO from an adjacent networkCVE-2022-28639 · HPE iLO 5 (adjacent-network code execution / DoS)High
- Intel Server Platform Services (SPS) firmware: Active debug code left enabled in shipped SPS firmware letsCVE-2022-36348 · Intel Server Platform Services (SPS) firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.