CVE-2025-66238
7.2Sunbird · DCIM dcTrack and IQ
Sunbird DCIM dcTrack and IQ contain an authentication bypass vulnerability allowing authenticated users to misuse remote access features to redirect network traffic.
Executive summary
A critical authentication bypass vulnerability in Sunbird DCIM dcTrack and IQ enables authenticated attackers to perform unauthorized network traffic redirection.
Vulnerability
The vulnerability is an authentication bypass using an alternate path or channel (CWE-288). An authenticated user with access to the appliance virtual console can exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.
Business impact
Successful exploitation of this flaw allows an attacker to gain unauthorized access to sensitive services or data by redirecting network traffic. Given the CVSS score of 7.2, this represents a high-severity risk to infrastructure management systems, potentially leading to a total compromise of the confidentiality and integrity of the affected appliance and its connected environment.
Remediation
Immediate Action: Update Sunbird DCIM dcTrack to version 9.2.3 and update Sunbird IQ to version 9.2.1 as recommended by the vendor.
Proactive Monitoring: Monitor network traffic logs for unusual redirection patterns or unauthorized access attempts originating from authenticated virtual console sessions.
Compensating Controls: Restrict access to the appliance virtual console to only authorized administrative personnel and ensure that the management network is isolated from general user traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability poses a substantial risk to the security of management infrastructure. Organizations utilizing Sunbird DCIM dcTrack and IQ are urged to prioritize the application of the vendor-provided patches. Immediate patching is the most effective method to eliminate the risk of unauthorized traffic redirection and maintain the integrity of the managed environment.
History
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 9.2.3 per CVE record
Sources
Originally found and disclosed by notnotnotveg (notnotnotveg@gmail.com) reported these vulnerabilities to CISA., per the CVE Program record.