Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platform
CVE-2023-3264Firmware, BMC & network fabriccurated
Impact
Hard-coded credentials in the DCIM platform; chained with the other PowerPanel flaws for full DCIM takeover and, from there, control of every managed power device in the facility
Who can reach it
Network
What to do
Upgrade PowerPanel Enterprise to 2.6.9; DCIM is often facility-operator-owned rather than tenant-owned, so a colocated neocloud may not control the remediation at all
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.