Database/Firmware, BMC & network fabric

Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by getting
Impact
CSRF in admin screens lets an authenticated attacker escalate privileges by getting an administrator to load a crafted page. dcTrack is the system of record for where every asset, circuit and outlet lives - so administrator access is both a map of the facility and, through its integrations, a route into the devices themselves.
Who can reach it
Requires an authenticated dcTrack administrator to visit an attacker-controlled page while logged in.
What to do
Upgrade dcTrack past 9.1.2. Software upgrade on one host. Also worth doing: check what credentials dcTrack holds for integrated PDU and power gear, since DCIM asset databases quietly accumulate device logins.
References
Related entries
- NVIDIA UFM Enterprise: code injection via the plugin management API from a low-privileged accountCVE-2026-24169 · NVIDIA UFM Enterprise (plugin management API)High
- librdmacm 1.0.16 (userspace RDMA connection-manager library) - default fallback to ibacm port 6125: RDMACVE-2012-4516 · librdmacm 1.0.16 (userspace RDMA connection-manager library) - default fallback to ibacm port 6125High
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-45745 · Intel TDX moduleHigh
- Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management): An unauthenticated local attackerCVE-2024-0172 · Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management)High
- AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena): SNP firmware fails to restrict where a hypervisor-drivenCVE-2024-21980 · AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena)High
- Intel reference platforms (Seamless Firmware Updates): A race condition in the seamless firmware update mechanism letsCVE-2024-23599 · Intel reference platforms (Seamless Firmware Updates)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.