GPU VulnDB

Database/Firmware, BMC & network fabric

Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40): Arbitrary code execution on the rack PDU

CVE-2020-11953Firmware, BMC & network fabriccurated

Impact

Arbitrary code execution on the rack PDU. Once code runs on the PDU, an attacker has a persistent presence on the OOB network that survives every host reimage in the rack, and direct control of outlet state - so this is both a persistence problem and a PHYSICAL availability problem.

Who can reach it

Network access to the PDU management interface.

What to do

Firmware flash per PDU. Because code execution means possible implantation, a unit you believe was targeted should be re-flashed from vendor image and its stored credentials rotated, not merely updated.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.