GPU VulnDB

Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection through

CVE-2023-3267Firmware, BMC & network fabricZDI-23-1149curated

Impact

OS command injection through the remote-backup username field, executing as NT AUTHORITY\SYSTEM. Chained behind either authentication bypass above, this is unauthenticated SYSTEM on the host that manages your UPS estate.

Who can reach it

Authenticated user adding a remote backup location - trivially reachable given the two auth bypasses in the same advisory batch.

What to do

Upgrade PowerPanel Enterprise. If the host was reachable from an untrusted network, rebuild it rather than patch - SYSTEM-level RCE on a Windows DCIM host means credential theft from the whole box.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.