Database/Firmware, BMC & network fabric
Riello NetMan 204: unauthenticated admin pages allow UPS shutdown and config disclosure
Impact
The NetMan 204 is the network card that puts a Riello UPS on the management network. Any unauthenticated request to its administrative pages returns configuration data, including LDAP settings and active user details, and the same unauthenticated path can invoke privileged UPS control commands - shutdown, reboot, switch-to-bypass and battery test. On a GPU floor that means an attacker who reaches the facilities VLAN can drop power to whatever the UPS feeds, or push it onto bypass so the next utility event is unprotected; a hard power loss on a rack of accelerators is a worst-case drain event, not a graceful one. The disclosed LDAP configuration also hands over directory details that are usually reused elsewhere in the management network.
Who can reach it
Anyone with network reach to the UPS management card's web interface - typically the facilities or management VLAN. No authentication and no credentials of any kind are required.
What to do
Treat this as firmware on an in-band facilities device: check the Riello NetMan 204 download page for a release that enforces authentication on the administrative pages and flash the card. Until then the only reliable control is network: remove the card from any routable segment, restrict it to a jump host ACL, and confirm no UPS management interface answers from tenant or general corporate networks. The record does not name a fixed version, so verify with the vendor before planning the flash window. Flashing the card does not interrupt the UPS load path, but schedule it alongside other facilities work since the card is the only remote shutdown control while it reboots.
References
Related entries
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCVE-2026-22696 · Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestation…Critical
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCVE-2026-44402 · Voltronic Power SNMP Web Pro 1.1 (upload.cgi firmware update endpoint)Critical
- fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCVE-2026-71566 · fakefish (Redfish BMC shim, KubeVirt backend)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): A user context could request the write-combine doorbell page repeatedlyCVE-2026-72495 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
- Phison PS3111-S11 SSD firmware: signature check trusts a modulus carried in the image, so any firmware verifiesCVE-2026-82876 · Phison PS3111-S11 SSD controller firmware (signature verification root of trust)Critical
- Phison PS3111-S11 SSD firmware: vendor unique commands allow persistent implants in controller flashCVE-2026-84696 · Phison PS3111-S11 SSD controller firmware (vendor unique commands over ATA)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.