Database/Firmware, BMC & network fabric

Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update tickets
Impact
Incorrect access control lets an attacker create or update tickets against locations they should not have access to, bypassing the RBAC check. In a multi-tenant colo or a shared cage environment, that is a tenant-boundary problem inside the facility workflow system - work orders touching another customer's rack.
Who can reach it
Any authenticated dcTrack user.
What to do
Upgrade past 9.1.2. If you run dcTrack with per-customer location scoping as a tenant-isolation control, treat that control as having been ineffective for the affected period and review the ticket history.
References
Related entries
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-38486 · Dell SmartFabric OS10 (command injection)High
- Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.c: The IB architecture says aCVE-2024-40992 · Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field): This is a straight kernel-stackCVE-2024-41079 · Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field)High
- Linux kernel InfiniBand core (ib_umad): ib_umad kept received management datagrams on an unbounded listCVE-2024-42145 · Linux kernel InfiniBand core (ib_umad)High
- AMI AptioV BIOS (TOCTOU race condition): Firmware TOCTOU race allowing execution of arbitrary code on the target deviceCVE-2024-42444 · AMI AptioV BIOS (TOCTOU race condition)High
- AMI AptioV BIOS (TOCTOU race condition): Second firmware TOCTOU race reaching arbitrary code execution with scope changeCVE-2024-42446 · AMI AptioV BIOS (TOCTOU race condition)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.