Database/Firmware, BMC & network fabric

Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): Least-privilege violation: low-privilege users on the PDU get
CVE-2020-11956Firmware, BMC & network fabriccurated
Impact
Least-privilege violation: low-privilege users on the PDU get far more capability than the role implies, up to and including control of the device. Read-only monitoring accounts handed to a DCIM system or an NOC contractor become power control.
Who can reach it
Any authenticated user on the PDU, including monitoring accounts.
What to do
Firmware update per PDU. Audit third-party accounts on the power estate at the same time - the monitoring integration is usually how the low-privilege credential got into someone else's hands.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.