Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platform
CVSS 6.7CVE-2023-3264Firmware, BMC & network fabriccurated
Impact
Hard-coded credentials in the DCIM platform; chained with the other PowerPanel flaws for full DCIM takeover and, from there, control of every managed power device in the facility
Who can reach it
Network
What to do
Upgrade PowerPanel Enterprise to 2.6.9; DCIM is often facility-operator-owned rather than tenant-owned, so a colocated neocloud may not control the remediation at all
References
Related entries
- EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds): Not a memory-safety bugCVE-2023-48733 · EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds)Medium
- Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27): An out-of-bounds read reachable by a privileged BMC userCVE-2023-49144 · Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27)Medium
- Micron Crucial MX500 series SSD, firmware M3CR046CVE-2024-42642 · Micron Crucial MX500 series SSD, firmware M3CR046 - buffer overflow in the drive controller reachable from host ATA…Medium
- Lenovo ThinkSystem UEFI/BIOS (SMM callout): A System Management Mode callout vulnerability in ThinkSystem UEFICVE-2024-45105 · Lenovo ThinkSystem UEFI/BIOS (SMM callout)Medium
- Lenovo ThinkSystem / ThinkStation (firmware buffer overflow): A local attacker with elevated privileges executesCVE-2024-4550 · Lenovo ThinkSystem / ThinkStation (firmware buffer overflow)Medium
- GRUB2 (JPEG parser): Out-of-bounds write in GRUB's JPEG parser from a crafted imageCVE-2024-45774 · GRUB2 (JPEG parser)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.