Database/Firmware, BMC & network fabric

Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reach
Impact
Whoever can reach the chiller's web card owns the chilled-water loop. The hard-coded credentials give direct control over the two operations that matter physically: switching the cooling unit off, and moving the water temperature setpoint. That is a thermal attack, not an IT one. A GB200 or H100 rack drawing 40-140 kW has essentially zero thermal mass at the die; pull chilled water away from the CDUs or rear-door heat exchangers feeding it and inlet temperature crosses the GPU thermal-shutdown threshold in single-digit minutes. Every job in the affected hall dies, unsaved training checkpoints are lost, and repeated thermal cycling degrades VRMs, HBM stacks and pump seals. The subtler and nastier variant is not shutdown but a slow setpoint drift: raise supply water two degrees and the fleet silently throttles, which shows up as unexplained tokens-per-second regression and blown SLA credits long before anyone looks at the chiller.
Who can reach it
Unauthenticated HTTP on whatever network the chiller's pCOWeb card is plugged into. In practice that is the facility/mechanical VLAN, which in a leased colo is the landlord's network, not the tenant's - so a GPU operator may have no visibility into it at all and no idea whether it is flat with the building's office LAN. In owned or built-to-suit sites this card is usually on the same mechanical VLAN as the CRAHs, the BMS front end and the vendor's remote-support jump box. Internet exposure is real but not the common case; the common case is that anyone who lands on any building-systems subnet can reach it, and the credentials are published.
What to do
There is no meaningful patch path - this is Carel pCOWeb OEM firmware embedded in a Rittal chiller, and the credentials are hard-coded. Realistic fix is network isolation: the chiller card goes on its own VLAN with an allow-list to exactly the BMS front end and nothing else, plus egress deny. If you lease space, you cannot patch this yourself; it is the landlord's mechanical plant. Put it in the contract - demand a network diagram for the mechanical VLAN, an attestation that no chiller/CRAH controller is reachable from any tenant or corporate network, and the right to have a third party validate it. Also demand that thermal-shutdown behaviour be tested: you need to know how many minutes you actually have, not a vendor's brochure number.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.