Database/Firmware, BMC & network fabric

Eaton Tripp Lite series PADM firmware (rack PDU / ATS management): Unauthenticated authentication bypass gives
Impact
Unauthenticated authentication bypass gives privileged access to the PDU management firmware. From a privileged session on a switched PDU an attacker controls outlet state for the rack - power-cycling nodes, or holding outlets off. Note the vendor has published an end-of-life notice for this product line alongside the advisory, which means for some deployed units the fix is replacement, not a patch.
Who can reach it
Unauthenticated, remote, against the PDU's management interface on the facility or OOB network.
What to do
Update PADM firmware where a fixed build exists. For SKUs covered by the EOL notice there is no forward-fix path and the remediation is hardware replacement - a capex line and a rack-by-rack electrical swap, not a maintenance window. Until then, isolate the PDU management network and disable remote outlet switching.
References
Related entries
- Arista EOS: crafted gNSI Credentialz request can grant an account privileges beyond what was configuredCVE-2026-73454 · Arista EOS gNSI Credentialz serviceHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-003-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-009-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksNCVD-2022-002-nvme-over-fabrics-protocol-over · NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmetHigh
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlCVE-2026-20898 · Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6High
- Intel Ethernet Adapter manageability firmware (access control): Improper access control in Intel Ethernet adapterCVE-2021-33162 · Intel Ethernet Adapter manageability firmware (access control)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.