Database/Control plane, storage & DevOps
Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attacker
Impact
Improper access control in Data Center Manager lets an unauthenticated attacker with adjacent network access escalate privilege. DCM is the fleet-wide power and thermal management plane - it holds credentials to platform management across every node it monitors, so compromising it is a lateral-movement jackpot rather than a single-host problem.
Who can reach it
Unauthenticated attacker on the same network segment as the DCM server. Whether that is a realistic position depends entirely on your management network segmentation.
What to do
Upgrade the Intel Data Center Manager software. This is a management-plane application, so the update is an application upgrade and service restart - no node drain, no firmware, no reboot of managed hosts. The real work is deciding what DCM is allowed to reach: it holds credentials for platform power and telemetry across the fleet, so its network exposure matters more than its version. Upgrade to 4.1 or later.
References
Related entries
- Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated userCVE-2022-21225 · Intel Data Center ManagerHigh
- MinIO: Non-admin user can create service accounts for root/admin users and assume their policiesCVE-2022-24842 · MinIOHigh
- HTCondor (CLAIMTOBE authentication method): Once a user has authenticated to a daemon with CLAIMTOBE - a method thatCVE-2022-26110 · HTCondor (CLAIMTOBE authentication method)High
- Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5: Unauthenticated program writesCVE-2022-30243 · Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5High
- Pure Storage Purity//FA and Purity//FB restricted shell (Python environment variables): A logged-in user manipulatesCVE-2022-32552 · Pure Storage Purity//FA and Purity//FB restricted shell (Python environment variables)High
- Pure Storage Purity//FA and Purity//FB restricted shell (environment variables): A second route out of the restrictedCVE-2022-32553 · Pure Storage Purity//FA and Purity//FB restricted shell (environment variables)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.