Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM - username handling: Authentication bypass: appending a non-printable character
Impact
Authentication bypass: appending a non-printable character to the built-in 'cyberpower' username logs an attacker straight in. Unauthenticated to full DCIM administrator, with no exploit development required. PowerPanel Enterprise manages UPS and PDU estates, so this is direct PHYSICAL exposure of the power layer.
Who can reach it
Unauthenticated, remote, against the PowerPanel Enterprise login. Anyone who can reach the web interface.
What to do
Upgrade PowerPanel Enterprise. Software upgrade on one host - genuinely cheap. Then check whether the default 'cyberpower' account exists at all and remove it. Get the DCIM off any network a tenant workload can route to.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.