DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.
History

Fri, 05 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sunbirddcim
Sunbirddcim dctrack
Sunbirddcim power Iq
Vendors & Products Sunbirddcim
Sunbirddcim dctrack
Sunbirddcim power Iq

Thu, 04 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.
Title Sunbird DCIM dcTrack and Power IQ Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-12-05T17:02:00.497Z

Reserved: 2025-11-25T17:32:15.110Z

Link: CVE-2025-66237

cve-icon Vulnrichment

Updated: 2025-12-05T17:01:52.475Z

cve-icon NVD

Status : Received

Published: 2025-12-04T21:16:09.137

Modified: 2025-12-04T21:16:09.137

Link: CVE-2025-66237

cve-icon Redhat

No data.