GPU VulnDB

Database/Firmware, BMC & network fabric

ATEN PE6208 switched PDU: The PDU ships with a default telnet account and never forces the operator to change

CVE-2023-43845Firmware, BMC & network fabriccurated

Impact

The PDU ships with a default telnet account and never forces the operator to change it on first login. Anyone who finds an un-rotated unit gets an administrator telnet session — full outlet control, including turning power off to whatever racks that PDU feeds.

Who can reach it

Network reachability to the PDU's telnet service plus knowledge of the published default credential; no exploit development needed.

What to do

Credential rotation is the immediate fix — audit every deployed PE6208 for the default telnet account and change it now. ATEN's firmware update additionally forces a credential change on first login for new deployments, so pair the audit with a firmware upgrade where feasible.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.