Database/Control plane, storage & DevOps

Rittal CMC III cabinet lock / access-card system: The access cards used to open control cabinets secured with Rittal
Impact
The access cards used to open control cabinets secured with Rittal CMC III locks can be cloned. In a datacenter this is the rack-level and cabinet-level access boundary - the CMC III system is exactly what many operators use to electronically lock individual racks and cabinets and to log who opened them, and it is often the control that lets a provider tell a customer 'only your staff can open your rack'. Cloning a card defeats that, and it defeats it invisibly: the lock logs a legitimate card opening a legitimate cabinet. Someone at an opened rack can pull NVMe drives holding model weights and customer data, attach a console to a node's serial or VGA port, plug into the out-of-band management switch that fronts every BMC in the row, or insert a hardware implant on a management link. The CVSS of 4.6 reflects the physical-access precondition, not the consequence - for a bare-metal GPU provider whose entire isolation story is physical, this is a boundary failure, and one that also breaks tenant handoff because the same credentials and the same locks carry across tenancies.
Who can reach it
Physical proximity to a valid card, then physical presence at the cabinet. No network access is involved. The precondition that matters is that the attacker must already be inside the hall - so this is the second stage after tailgating, a compromised hall-door credential, or legitimate access as a contractor, landlord technician, or another tenant's staff in a shared hall.
What to do
Not fixable by patching - it is the credential technology. Rittal's guidance is to move to a more secure card technology where the hardware supports it; in practice that means replacing readers and reissuing cards, a per-cabinet hardware cost. Compensating controls that work today: tamper alarms on cabinet doors wired into a system separate from the lock itself, camera coverage of aisles with retention long enough to review, and a policy that any cabinet-open event is reconciled against a work order rather than just logged. In a shared hall, treat the cabinet lock as a deterrent rather than a boundary, and put anything that genuinely requires isolation behind a full cage with a second access factor.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.