CVE-2025-41426
CVSS 9.8 CRITICAL: affected Vertiv products contain a stack based buffer overflow vulnerability. EPSS 0.8% (52º percentile).
Vulnerabilità ed exploit
Il punto debole è la scheda di gestione UPS, non l'hardware del rack. Se un attaccante entra in quel piano amministrativo, la scheda può diventare un punto di controllo per la continuità dell'alimentazione, il che ნიშნავს che uno shutdown pulito o un uptime stabile non sono più garantiti.
2 fonti · 11 giu
CVSS 9.8 CRITICAL: affected Vertiv products contain a stack based buffer overflow vulnerability. EPSS 0.8% (52º percentile).
CVSS 9.8 CRITICAL: affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass… EPSS 0.6% (45º percentile).
Industrial Cyber
Claroty finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations - Industrial Cyber
Claroty's Team82 finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations.
originaleSecurityWeek
Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers
Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller.
originalePart of the PlainSec briefing for 2026-06-11
Every edition of this story: Le schede UPS diventano un rischio di controllo dell'alimentazione