GPU VulnDB

Database/Firmware, BMC & network fabric

Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by getting

CVE-2024-37774Firmware, BMC & network fabriccurated

Impact

CSRF in admin screens lets an authenticated attacker escalate privileges by getting an administrator to load a crafted page. dcTrack is the system of record for where every asset, circuit and outlet lives - so administrator access is both a map of the facility and, through its integrations, a route into the devices themselves.

Who can reach it

Requires an authenticated dcTrack administrator to visit an attacker-controlled page while logged in.

What to do

Upgrade dcTrack past 9.1.2. Software upgrade on one host. Also worth doing: check what credentials dcTrack holds for integrated PDU and power gear, since DCIM asset databases quietly accumulate device logins.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.