Database/Firmware, BMC & network fabric

APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmware: A heap overflow in
Impact
A heap overflow in TLS packet reassembly gives an attacker code execution on the UPS's own controller - the device that decides whether your racks get power. From there an attacker can cut output, refuse to transfer to battery during a utility event, or (as Armis demonstrated on the bench) drive the unit until it physically burns. This is not a monitoring card compromise; it is the power train. A single UPS covering a GPU row kills every training job in that row with no checkpoint.
Who can reach it
Unauthenticated. The UPS initiates an outbound TLS connection to Schneider's cloud service, so an attacker who can intercept or MITM that connection - or who is simply on the same network segment as the UPS management port - reaches the vulnerable parser. No credentials, no prior foothold on the compute network.
What to do
Firmware flash on every affected UPS, pushed through the Schneider update tool or the cloud service. Cost is real: each unit must be updated individually and some models require the load to be transferred or the unit taken to bypass first, so this is a scheduled electrical maintenance window per unit, not a fleet-wide push. If you cannot patch promptly, block the UPS's outbound path to the SmartConnect cloud and put the management port on an isolated VLAN with no route to the internet.
References
Related entries
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machine: A TLS authentication bypass byCVE-2022-22806 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machineCritical
- Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remoteCVE-2024-45764 · Dell Enterprise SONiC (authentication)Critical
- Arista EOS OSPFv3: crafted packet restarts the routing agentCVE-2026-73455 · Arista EOS (OSPFv3 routing agent)High
- Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c): The canonical RDMA isolationCVE-2014-8159 · Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c)High
- Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes theCVE-2016-5685 · Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injectionHigh
- Cisco NX-OS / FXOS (LLDP parser): A malformed LLDP frame reloads the switch. LLDP is enabled by default on essentiallyCVE-2018-0395 · Cisco NX-OS / FXOS (LLDP parser)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.