Sunbird DCIM dcTrack and Power IQ Authentication Bypass Using an Alternate Path or Channel
Vulnerability Description
DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66238
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- notnotnotveg (notnotnotveg@gmail.com) reported these vulnerabilities to CISA.
References
Affected Vendor
Sunbird
View all reports →