Database/Firmware, BMC & network fabric

Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by getting
Impact
CSRF in admin screens lets an authenticated attacker escalate privileges by getting an administrator to load a crafted page. dcTrack is the system of record for where every asset, circuit and outlet lives - so administrator access is both a map of the facility and, through its integrations, a route into the devices themselves.
Who can reach it
Requires an authenticated dcTrack administrator to visit an attacker-controlled page while logged in.
What to do
Upgrade dcTrack past 9.1.2. Software upgrade on one host. Also worth doing: check what credentials dcTrack holds for integrated PDU and power gear, since DCIM asset databases quietly accumulate device logins.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.