DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.
History

Fri, 05 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sunbirddcim
Sunbirddcim dctrack
Sunbirddcim power Iq
Vendors & Products Sunbirddcim
Sunbirddcim dctrack
Sunbirddcim power Iq

Thu, 04 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.
Title Sunbird DCIM dcTrack and Power IQ Authentication Bypass Using an Alternate Path or Channel
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-12-05T17:01:14.562Z

Reserved: 2025-11-25T17:32:15.110Z

Link: CVE-2025-66238

cve-icon Vulnrichment

Updated: 2025-12-05T17:01:11.411Z

cve-icon NVD

Status : Received

Published: 2025-12-04T22:15:49.320

Modified: 2025-12-04T22:15:49.320

Link: CVE-2025-66238

cve-icon Redhat

No data.