GPU VulnDB

Database/Firmware, BMC & network fabric

CyberPower PowerPanel Enterprise DCIM - username handling: Authentication bypass: appending a non-printable character

CVE-2023-3265Firmware, BMC & network fabricZDI-23-1147curated

Impact

Authentication bypass: appending a non-printable character to the built-in 'cyberpower' username logs an attacker straight in. Unauthenticated to full DCIM administrator, with no exploit development required. PowerPanel Enterprise manages UPS and PDU estates, so this is direct PHYSICAL exposure of the power layer.

Who can reach it

Unauthenticated, remote, against the PowerPanel Enterprise login. Anyone who can reach the web interface.

What to do

Upgrade PowerPanel Enterprise. Software upgrade on one host - genuinely cheap. Then check whether the default 'cyberpower' account exists at all and remove it. Get the DCIM off any network a tenant workload can route to.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.