Database/Control plane, storage & DevOps

CyberPower PowerPanel managed devices - shared device certificates: Every managed device uses an identical certificate
Impact
Every managed device uses an identical certificate derived from a hardcoded key, so any device can impersonate any other. An attacker who compromises one PDU in one rack can pose as every other device in the estate and feed the DCIM whatever telemetry they like - including telling it everything is fine while a hall overheats, or triggering automated responses that are themselves PHYSICAL actions.
Who can reach it
Anyone who obtains the key - which means anyone who obtains any single managed device, including a unit bought secondhand or pulled from an RMA pile.
What to do
Vendor firmware and platform upgrade that issues per-device certificates. Until then, the device identity layer provides no assurance and you should not build automated power actions on top of it. Note this also breaks the trust assumption in your decommissioning process: a device leaving your estate carries the fleet key with it.
References
Related entries
- Keycloak: SAML signature scope determined by position, not ReferenceCVE-2024-8698 · KeycloakHigh
- Tridium Niagara Framework and Niagara Enterprise Security (before 4.10.11 / 4.14.2 / 4.15.1): A chain, not a singleCVE-2025-3937 · Tridium Niagara Framework and Niagara Enterprise Security (before 4.10.11 / 4.14.2 / 4.15.1)High
- GitLab CE/EE: environment scope matching lets an authenticated user read CI/CD variables outside their scopeCVE-2026-13210 · GitLab CE/EE (CI/CD environment scope pattern matcher)High
- BOSH vSphere CPI: missing certificate pinning lets an interceptor impersonate vCenter and capture admin credentialsCVE-2026-41012 · BOSH Director vSphere CPI (vCenter REST API certificate validation)High
- OpenTelemetry Operator TargetAllocator: a tenant ServiceMonitor can exfiltrate the Collector's service-account tokenCVE-2026-47701 · OpenTelemetry Operator TargetAllocator (ServiceMonitor bearerTokenFile handling)High
- Dell OpenManage Server Administrator (improper authentication): An unauthenticated remote attacker gets unauthorizedCVE-2026-56793 · Dell OpenManage Server Administrator (improper authentication)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.