Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection through
Impact
OS command injection through the remote-backup username field, executing as NT AUTHORITY\SYSTEM. Chained behind either authentication bypass above, this is unauthenticated SYSTEM on the host that manages your UPS estate.
Who can reach it
Authenticated user adding a remote backup location - trivially reachable given the two auth bypasses in the same advisory batch.
What to do
Upgrade PowerPanel Enterprise. If the host was reachable from an untrusted network, rebuild it rather than patch - SYSTEM-level RCE on a Windows DCIM host means credential theft from the whole box.
References
Related entries
- AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP headerCVE-2023-34329 · AMI MegaRAC SPx12 (BMC&C)Critical
- Arista EOS (secure VXLAN / Tunnelsec agent): After the Tunnelsec agent restarts, traffic that should be encryptedCVE-2024-12378 · Arista EOS (secure VXLAN / Tunnelsec agent)Critical
- Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module link: The iSTARCVE-2024-32752 · Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module linkCritical
- The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendors: An attackerCVE-2024-3411 · The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendorsCritical
- Dell Enterprise SONiC (OS command injection): OS command injection giving arbitrary command execution on the switch'sCVE-2024-45763 · Dell Enterprise SONiC (OS command injection)Critical
- Dell Enterprise SONiC (privilege boundary in CLI): High-privilege OS commands can be run by users holding lessCVE-2024-45765 · Dell Enterprise SONiC (privilege boundary in CLI)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.