GPU VulnDB

Database/Firmware, BMC & network fabric

ATEN PE8108 switched PDU: TENANT ISOLATION: a restricted (non-admin) user account on the PDU's web interface can control

CVE-2023-25409Firmware, BMC & network fabriccurated

Impact

TENANT ISOLATION: a restricted (non-admin) user account on the PDU's web interface can control outlets belonging to other users — meaning one tenant sharing this PDU with others can power-cycle or power-off outlets feeding another tenant's equipment, not just their own.

Who can reach it

Requires only a low-privileged, restricted user account on the PDU — no admin credentials needed to reach outlets outside the account's assigned scope.

What to do

Firmware upgrade from ATEN to a version that enforces per-outlet authorization correctly. Flash each PDU; since this is the power path for the racks it feeds, coordinate the maintenance window with anyone whose equipment is on that PDU.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.