Database/Control plane, storage & DevOps

CyberPower PowerPanel Business - default.cmd file upload: Unrestricted upload of a dangerous file type into default.cmd
Impact
Unrestricted upload of a dangerous file type into default.cmd - the script PowerPanel runs on a power event. Same nasty shape as the PowerChute issue: the attacker's code runs at the moment the UPS signals, across every host the software controls, with elevated privilege. The trigger is a power event, which an attacker with UPS access can also cause.
Who can reach it
An attacker who can write to the PowerPanel Business installation - reachable via the default-credential issue in the same advisory.
What to do
Upgrade past v4.8.6. Independently: shutdown scripts invoked by power-management software are privileged code and should be under change control with restricted write permissions, on every host, regardless of vendor.
References
Related entries
- HAProxy (before 2.7.3): HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to makeCVE-2023-25725 · HAProxy (before 2.7.3)Critical
- DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation): A deviceCVE-2023-31127 · DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation)Critical
- Samba: Path traversal in client pipe namesCVE-2023-3961 · SambaCritical
- Lustre (incorrect access control, 2.13.x-2.15.x before 2.15.4): Incorrect access control in Lustre lets an attackerCVE-2023-51786 · Lustre (incorrect access control, 2.13.x-2.15.x before 2.15.4)Critical
- Pure Storage FlashArray Purity (remote administrative account creation): An attacker uses a remote administrativeCVE-2024-0003 · Pure Storage FlashArray Purity (remote administrative account creation)Critical
- Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitraryCVE-2024-0004 · Pure Storage FlashArray Purity (array admin command execution)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.