Database/Firmware, BMC & network fabric

ATEN PE6208 switched PDU: The PDU ships with a default telnet account and never forces the operator to change
Impact
The PDU ships with a default telnet account and never forces the operator to change it on first login. Anyone who finds an un-rotated unit gets an administrator telnet session — full outlet control, including turning power off to whatever racks that PDU feeds.
Who can reach it
Network reachability to the PDU's telnet service plus knowledge of the published default credential; no exploit development needed.
What to do
Credential rotation is the immediate fix — audit every deployed PE6208 for the default telnet account and change it now. ATEN's firmware update additionally forces a credential change on first login for new deployments, so pair the audit with a firmware upgrade where feasible.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/srp): The SRP abort handler completes the SCSI command itself, after which theCVE-2023-52515 · Linux kernel (drivers/infiniband/ulp/srp)Critical
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/xsk): An RX buffer on the legacy receive queue is releasedCVE-2023-54223 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/xsk)Critical
- Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6): An attacker who never authenticatesCVE-2024-36435 · Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server builds an RDMA work request around a scatter-gather listCVE-2024-36476 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt): An inbound response packet is queued to the completerCVE-2024-38544 · Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt)Critical
- OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427): slpd-lite is a small SLP responder that OpenBMC installsCVE-2024-41660 · OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.