Database/Control plane, storage & DevOps
Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack buffer
Impact
Unauthenticated remote attacker overflows a stack buffer in the CMC and gains control of the chassis manager - the component that owns power, identity and console for every sled in the enclosure.
Who can reach it
Network access to the CMC management interface, no credentials required.
What to do
Update CMC firmware to 2.40.200.202101130302 (FX2) or 3.41.200.202209300499 (VRTX). Firmware flash on the chassis controller; sleds keep running but management is interrupted. If these chassis are reachable from anything but a locked-down OOB VLAN, fix that first - it is the actual exposure.
References
Related entries
- VMware Avi Load Balancer: authorization bypass exposes part of the Avi Controller control planeCVE-2026-47866 · VMware Avi Load Balancer (Avi Controller control plane)High
- Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodesCVE-2026-54100 · Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key)High
- Coder: workspace agent redirects let one tenant read, write and execute in another's workspaceCVE-2026-63443 · Coder (workspace agent API client, agentConn.apiClient redirect handling)High
- Renovate: mutual-TLS private key written to logs in cleartext when it appears outside its own fieldCVE-2026-88883 · Renovate self-hosted (log redaction of hostRules[].httpsPrivateKey)High
- IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport): An attacker who can speak to the cluster'sCVE-2020-4927 · IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport)High
- Ivanti Connect Secure: Web-component authentication bypass reaching restricted resourcesCVE-2023-46805 · Ivanti Connect SecureHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.