Database/Firmware, BMC & network fabric

ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned role
Impact
The web interface doesn't check a user's assigned role before acting on their requests, so an authenticated low-privileged user can escalate to actions normally reserved for administrators on the datacenter-infrastructure-management platform — which typically has visibility and control hooks into PDUs and environmental sensors across the facility.
Who can reach it
Requires a valid but low-privileged account on ATEN eco DC; the attacker sends requests for admin-level functions that the server fails to gate on role.
What to do
Software upgrade to the patched eco DC release per ATEN's advisory. This is a server-side application (not per-rack firmware), so it's a single upgrade rather than a fleet-wide rollout, but audit who has any account on it since the bug turns any low-privileged login into an admin one.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.