GPU VulnDB

Database/Firmware, BMC & network fabric

Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update tickets

CVE-2024-37775Firmware, BMC & network fabriccurated

Impact

Incorrect access control lets an attacker create or update tickets against locations they should not have access to, bypassing the RBAC check. In a multi-tenant colo or a shared cage environment, that is a tenant-boundary problem inside the facility workflow system - work orders touching another customer's rack.

Who can reach it

Any authenticated dcTrack user.

What to do

Upgrade past 9.1.2. If you run dcTrack with per-customer location scoping as a tenant-isolation control, treat that control as having been ineffective for the affected period and review the ticket history.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.