CVE-2025-41426
CVSS 9.8 CRITICAL: affected Vertiv products contain a stack based buffer overflow vulnerability. EPSS 0.8% (52º percentile).
Vulnerabilità · 110 giorni fa
Il punto debole è la scheda di gestione UPS, non l'hardware del rack. Se un attaccante entra in quel piano amministrativo, la scheda può diventare un punto di controllo per la continuità dell'alimentazione, il che ნიშნავს che uno shutdown pulito o un uptime stabile non sono più garantiti.
CVSS 9.8 CRITICAL: affected Vertiv products contain a stack based buffer overflow vulnerability. EPSS 0.8% (52º percentile).
CVSS 9.8 CRITICAL: affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass… EPSS 0.6% (45º percentile).
2 fonti che coprono questa storia
Claroty's Team82 finds authentication bypass, RCE flaws in Vertiv UPS management cards that could disrupt data center operations.
Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers
Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller.
Part of the PlainSec briefing for 2026-06-12