Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM - username handling: Authentication bypass: appending a non-printable character
Impact
Authentication bypass: appending a non-printable character to the built-in 'cyberpower' username logs an attacker straight in. Unauthenticated to full DCIM administrator, with no exploit development required. PowerPanel Enterprise manages UPS and PDU estates, so this is direct PHYSICAL exposure of the power layer.
Who can reach it
Unauthenticated, remote, against the PowerPanel Enterprise login. Anyone who can reach the web interface.
What to do
Upgrade PowerPanel Enterprise. Software upgrade on one host - genuinely cheap. Then check whether the default 'cyberpower' account exists at all and remove it. Get the DCIM off any network a tenant workload can route to.
References
Related entries
- CyberPower PowerPanel Enterprise DCIM - LDAP authentication path: If LDAP authentication is selectedCVE-2023-3266 · CyberPower PowerPanel Enterprise DCIM - LDAP authentication pathCritical
- Supermicro BMC email/SMTP alert notification handler (H12DST-B): Command execution as root on the BMC, reached throughCVE-2023-35861 · Supermicro BMC email/SMTP alert notification handler (H12DST-B)Critical
- Juniper Junos OS J-Web (EX/SRX): Unauthenticated remote code execution by setting `PHPRC` through a crafted J-WebCVE-2023-36845 · Juniper Junos OS J-Web (EX/SRX)Critical
- Insyde InsydeH2O (AsfSecureBootDxe): Stack buffer overflow leading to arbitrary code execution during the DXE phaseCVE-2023-39281 · Insyde InsydeH2O (AsfSecureBootDxe)Critical
- lldpd (CDP PDU parser, cdp_decode): A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpdCVE-2023-41910 · lldpd (CDP PDU parser, cdp_decode)Critical
- Broadcom LSI Storage Authority (LSA) / Intel RAID Web Console 3 (RWC3)CVE-2023-4323 · Broadcom LSI Storage Authority (LSA) / Intel RAID Web Console 3 (RWC3) - management service for MegaRAID and LSI HBA…Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.