GPU VulnDB

Database/Control plane, storage & DevOps

APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reports

CVE-2020-7526Control plane, storage & DevOpsSEVD-2020-192-01curated

Impact

PowerChute runs the shutdown script that fires when a UPS reports a power event. Improper input validation means an attacker can get arbitrary code executed at exactly that moment - during a shutdown, with elevated privilege, on every host running the agent. It is a rare shape of bug: the trigger is a power event you cannot prevent, and the payload runs fleet-wide simultaneously.

Who can reach it

Requires the ability to influence the shutdown script content or the event that invokes it - which in practice means access to the PowerChute management server or the UPS that signals it.

What to do

Upgrade PowerChute. Agent upgrade across every host that runs it, so this is a fleet-wide package push - schedulable, but it touches every node. Separately, treat shutdown scripts as privileged code: version them, restrict who can edit them, and do not let the UPS management network write to them.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.