GPU VulnDB

Database/Firmware, BMC & network fabric

APC Easy UPS Online Monitoring Software (Windows and Windows Server): PHYSICAL. Critical functions in the UPS

CVE-2022-42970Firmware, BMC & network fabricSEVD-2022-256-01curated

Impact

PHYSICAL. Critical functions in the UPS monitoring server are exposed with no authentication at all. This software is what issues graceful-shutdown commands to hosts and controls UPS behaviour - so an attacker who reaches it can trigger a coordinated shutdown of everything the software manages. On a GPU fleet that is a clean, deniable way to kill every running job at once, no memory corruption required.

Who can reach it

Unauthenticated, over the network to the monitoring server. This software typically runs on a Windows box on the facility or management network with wide reachability, because it needs to talk to every UPS and every managed host.

What to do

Upgrade the monitoring software (SEVD-2022-256-01). This is a server-side upgrade rather than device firmware, so it is cheap - a reboot of one Windows host, not a maintenance window on the power train. The harder work is the network position: this box should not be reachable from the compute network or from tenant-facing subnets, and its shutdown-command channel should be authenticated.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.