Database/Control plane, storage & DevOps

CyberPower PowerPanel Business - default.cmd file upload: Unrestricted upload of a dangerous file type into default.cmd
Impact
Unrestricted upload of a dangerous file type into default.cmd - the script PowerPanel runs on a power event. Same nasty shape as the PowerChute issue: the attacker's code runs at the moment the UPS signals, across every host the software controls, with elevated privilege. The trigger is a power event, which an attacker with UPS access can also cause.
Who can reach it
An attacker who can write to the PowerPanel Business installation - reachable via the default-credential issue in the same advisory.
What to do
Upgrade past v4.8.6. Independently: shutdown scripts invoked by power-management software are privileged code and should be under change control with restricted write permissions, on every host, regardless of vendor.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.