GPU VulnDB

Database/Control plane, storage & DevOps

APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the web

CVE-2024-58310Control plane, storage & DevOpscurated

Impact

An unauthenticated attacker can manipulate URL parameters to walk out of the web root and read arbitrary system files off the card, including files like /etc/passwd — enough to harvest system account information and plan a follow-on attack against the UPS/PDU's management plane.

Who can reach it

Fully remote and unauthenticated — a crafted HTTP request with encoded directory-traversal sequences is enough.

What to do

Firmware flash of the NMC4 card to the fixed release. Roll out per card; the UPS/PDU keeps serving power to its load during the flash, but remote monitoring/management of that unit drops briefly.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.