Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version
affected
Default status
unaffected
Any version
affected
Description
Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
Any version
Any version
Credits
Vera Mens of Claroty Team82 reported this these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-140-10
www.vertiv.com/en-us/support/security-support-center/