GPU VulnDB

Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM - LDAP authentication path: If LDAP authentication is selected

CVE-2023-3266Firmware, BMC & network fabricZDI-23-1148curated

Impact

If LDAP authentication is selected, the authentication mechanism is incomplete and every check can be bypassed. The operators most likely to be affected are the mature ones - the ones who wired their DCIM into corporate directory rather than using local accounts. Doing the responsible thing is what turns the bug on.

Who can reach it

Unauthenticated, remote, on any PowerPanel Enterprise instance configured for LDAP.

What to do

Upgrade PowerPanel Enterprise immediately. As an interim, switching off LDAP mode removes the vulnerable path but costs you central account control - a genuinely unpleasant trade, so prioritise the upgrade.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.