CVE Vulnerabilities

CVE-2025-66238

Authentication Bypass Using an Alternate Path or Channel

Published: Dec 04, 2025 | Modified: Dec 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliances virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References