Database/Control plane, storage & DevOps

Vertiv (stack-based buffer overflow, code execution): A stack overflow gives an attacker code execution on the Vertiv
CVSS 9.8CVE-2025-41426Control plane, storage & DevOpscurated
Impact
A stack overflow gives an attacker code execution on the Vertiv facility device - persistent control of rack power/environmental infrastructure.
Who can reach it
Network access to the affected device.
What to do
Apply the Vertiv firmware update per ICSA-25-140-10 and isolate facility devices onto their own network segment.
References
Related entries
- Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cards: Authentication bypass plusCVE-2025-46412 · Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cardsCritical
- Teleport: Remote authentication bypass in Teleport Community Edition (<=17.5.1)CVE-2025-49825 · TeleportCritical
- F5 BIG-IP (APM access policy): Specific malicious traffic against a virtual server with a BIG-IP APM access policyCVE-2025-53521 · F5 BIG-IP (APM access policy)Critical
- Citrix NetScaler ADC / Gateway (configured as VPN Gateway, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server): A memoryCVE-2025-6543 · Citrix NetScaler ADC / Gateway (configured as VPN Gateway, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server)Critical
- Lantronix EDS5000 serial-to-Ethernet device server: Root command execution on the device serverCVE-2025-67038 · Lantronix EDS5000 serial-to-Ethernet device serverCritical
- Marvell QConvergeConsole (QLogic Fibre Channel / FC-NVMe / CNA HBA management web console), 5.5.0.78 and earlierCVE-2025-6802 · Marvell QConvergeConsole (QLogic Fibre Channel / FC-NVMe / CNA HBA management web console), 5.5.0.78 and earlierCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.