Database/Control plane, storage & DevOps

APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reports
Impact
PowerChute runs the shutdown script that fires when a UPS reports a power event. Improper input validation means an attacker can get arbitrary code executed at exactly that moment - during a shutdown, with elevated privilege, on every host running the agent. It is a rare shape of bug: the trigger is a power event you cannot prevent, and the payload runs fleet-wide simultaneously.
Who can reach it
Requires the ability to influence the shutdown script content or the event that invokes it - which in practice means access to the PowerChute management server or the UPS that signals it.
What to do
Upgrade PowerChute. Agent upgrade across every host that runs it, so this is a fleet-wide package push - schedulable, but it touches every node. Separately, treat shutdown scripts as privileged code: version them, restrict who can edit them, and do not let the UPS management network write to them.
References
Related entries
- Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1: Authenticated file uploadCVE-2020-7569 · Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1High
- Nagios XI: OS command injection in the windowswmi config wizard (authenticated)CVE-2021-25296 · Nagios XIHigh
- Nagios XI: OS command injection in the switch config wizardCVE-2021-25297 · Nagios XIHigh
- Nagios XI: OS command injection in the cloud-vm config wizardCVE-2021-25298 · Nagios XIHigh
- HTCondor (IDTOKENS authentication): A flaw in IDTOKENS lets a user authenticate as another user or as the condorCVE-2021-25312 · HTCondor (IDTOKENS authentication)High
- linuxptp / ptp4l (PTP message forwarding): A missing length check when ptp4l forwards a PTP message between ports leaksCVE-2021-3570 · linuxptp / ptp4l (PTP message forwarding)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.