GPU VulnDB

Database/Firmware, BMC & network fabric

Eaton Tripp Lite series PADM firmware (rack PDU / ATS management): PHYSICAL. Unauthenticated authentication bypass

CVE-2026-22620Firmware, BMC & network fabriceaton-va-2026-1005curated

Impact

PHYSICAL. Unauthenticated authentication bypass gives privileged access to the PDU management firmware. From a privileged session on a switched PDU an attacker controls outlet state for the rack - power-cycling nodes, or holding outlets off. Note the vendor has published an end-of-life notice for this product line alongside the advisory, which means for some deployed units the fix is replacement, not a patch.

Who can reach it

Unauthenticated, remote, against the PDU's management interface on the facility or OOB network.

What to do

Update PADM firmware where a fixed build exists. For SKUs covered by the EOL notice there is no forward-fix path and the remediation is hardware replacement - a capex line and a rack-by-rack electrical swap, not a maintenance window. Until then, isolate the PDU management network and disable remote outlet switching.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.