Database/Firmware, BMC & network fabric

Eaton Tripp Lite series PADM firmware, session management interface: An authenticated administrator can break out
Impact
An authenticated administrator can break out of the restricted shell and run arbitrary commands on the PDU. That turns a device you thought was an appliance into a persistent Linux foothold sitting on your out-of-band network, below every server it powers and outside any endpoint tooling you run.
Who can reach it
Requires administrator credentials on the PDU - which, given the companion authentication bypass, an unauthenticated attacker can obtain first. Chain the two and this is unauthenticated remote code execution on rack power infrastructure.
What to do
PADM firmware update, or hardware replacement for EOL SKUs. Rotate PDU admin credentials, which are very commonly shared fleet-wide from the original commissioning.
References
Related entries
- Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesCVE-2026-22622 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- IBM BladeCenter AMM (before 3.66E), IMM (before 1.43), IMM2: The in-band host-to-BMC pivot, with a CVE attached. TheCVE-2014-0860 · IBM BladeCenter AMM (before 3.66E), IMM (before 1.43), IMM2High
- Power Management Controller (PMC) firmware in systems using Intel CSME 11.x/12.0 or Intel SPS 4.x: An administrativeCVE-2018-3643 · Power Management Controller (PMC) firmware in systems using Intel CSME 11.x/12.0 or Intel SPS 4.xHigh
- BMC firmware on Intel server boards, compute modules and systems - SMBus access control: An attackerCVE-2018-3682 · BMC firmware on Intel server boards, compute modules and systems - SMBus access controlHigh
- GRUB2: Buffer overflow in `grub.cfg` parsing allowing Secure Boot bypass and arbitrary code execution inside GRUBCVE-2020-10713 · GRUB2High
- GRUB2 (direct kernel boot without shim): When GRUB is booted directly by UEFI rather than chained through shim, it doesCVE-2020-15705 · GRUB2 (direct kernel boot without shim)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.