GPU VulnDB

Database/Control plane, storage & DevOps

Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior): No rate limiting

CVE-2022-43377Control plane, storage & DevOpsCVE-2022-43376CVE-2022-43378SEVD-2022-312-01curated

Impact

No rate limiting on authentication, so an attacker brute-forces the account and takes over the appliance, with stored XSS and clickjacking issues alongside it that let them hit an administrator's browser session. NetBotz appliances are the environmental eyes of the room - temperature, humidity, airflow, leak detection under liquid-cooled racks, door sensors, and camera pods. Control of one means the attacker decides what the operations team sees. During a cooling attack that is decisive: the temperature curve on the wall display stays flat while inlet temperatures climb toward the GPU thermal-shutdown threshold, and the first real signal is accelerators dropping off the fabric. The camera pods are a second concern - a NetBotz with camera modules is a video feed into the hall and the cage aisles, which is both a surveillance-evasion tool for someone about to walk in and a privacy exposure. Leak detection matters specifically for direct-liquid-cooled GPU racks, where a suppressed leak alarm is a route to real hardware destruction.

Who can reach it

Network access to the appliance's web interface, unauthenticated for the brute-force. NetBotz units sit on the facility monitoring VLAN, are polled by DCIM, and are frequently reachable from the corporate network because facilities staff want the camera feed. Weak or default passwords on these appliances are extremely common because they are installed once and never revisited.

What to do

Firmware update to a fixed NetBotz 4 release per Schneider's SEVD-2022-312-01 - straightforward appliance firmware, no cooling impact, so schedule it. Then do the part that actually closes the brute-force risk regardless of version: set a strong unique password per appliance (they are usually all identical across a site), disable unused accounts, and put the appliance behind an ACL permitting only the DCIM collector and a jump host. Treat environmental telemetry integrity as a control objective in its own right - if the only temperature data you have comes from appliances on the same VLAN as everything else, you have no independent way to detect a cooling attack, so consider a second, separately-networked temperature source for critical GPU rows.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.