Database/Firmware, BMC & network fabric

Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalates
Impact
A low-privilege authenticated user escalates to unrestricted device access. In practice that means a read-only monitoring account - the kind operators hand to a DCIM tool or an NOC vendor - becomes full control of rack power.
Who can reach it
Any authenticated user on the PDU, including the shared read-only accounts typically configured for monitoring integrations.
What to do
PADM firmware update or replacement for EOL SKUs. Separately, audit which third parties hold PDU accounts - monitoring integrations are the usual source of the low-privilege credential this bug needs.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.