Home

Description

DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

PUBLISHED Reserved 2025-11-25 | Published 2025-12-04 | Updated 2025-12-05 | Assigner icscert




HIGH: 7.4CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-288 Authentication Bypass Using an Alternate Path or Channel

Product status

Default status
unaffected

Any version
affected

9.2.3
unaffected

Default status
unaffected

Any version
affected

9.2.1
unaffected

Credits

notnotnotveg (notnotnotveg@gmail.com) reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-25-338-05

github.com/...p/csaf_files/OT/white/2025/icsa-25-338-05.json

cve.org (CVE-2025-66238)

nvd.nist.gov (CVE-2025-66238)