Database/Firmware, BMC & network fabric

ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned role
Impact
The web interface doesn't check a user's assigned role before acting on their requests, so an authenticated low-privileged user can escalate to actions normally reserved for administrators on the datacenter-infrastructure-management platform — which typically has visibility and control hooks into PDUs and environmental sensors across the facility.
Who can reach it
Requires a valid but low-privileged account on ATEN eco DC; the attacker sends requests for admin-level functions that the server fails to gate on role.
What to do
Software upgrade to the patched eco DC release per ATEN's advisory. This is a server-side application (not per-rack firmware), so it's a single upgrade rather than a fleet-wide rollout, but audit who has any account on it since the bug turns any low-privileged login into an admin one.
References
Related entries
- Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulatesCVE-2025-8557 · Lenovo XClarity Orchestrator (alternate communication channel)High
- Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injectionCVE-2026-14371 · Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection)High
- OpenBMC phosphor-net-ipmid: session authorization can be swapped to another account without re-authenticatingCVE-2026-16140 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RAKP session authorization)High
- Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commandsCVE-2026-16793 · Lenovo XClarity Orchestrator (OS command injection)High
- Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesCVE-2026-22622 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric managerCVE-2026-24170 · NVIDIA UFM Enterprise (web interface authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.