Connect with us

News

Trellix Advanced Research Center Uncovers Vulnerabilities in Data Center Infrastructure

Published

on

Trellix

As part of a focused effort on vulnerability discovery in data centers, the Trellix Advanced Research Center has found four vulnerabilities in CyberPower’s Data Center Infrastructure Management (DCIM) platform and five vulnerabilities in Dataprobe’s iBoot Power Distribution Unit (PDU). An attacker could chain these vulnerabilities together to gain full access to these systems — which alone could be leveraged to commit substantial damage. Furthermore, both products are vulnerable to remote code injection that could be leveraged to create a backdoor or an entry point to the broader network of connected data center devices and enterprise systems.

CyberPower is a leading vendor of data center equipment and infrastructure solutions, specializing in power protection technologies and power management systems. Their DCIM platform allows IT teams to manage, configure, and monitor the infrastructure within a data center through the cloud, serving as a single source of information and control for all devices. These platforms are commonly used by companies managing on-premise server deployments to larger, co-located data centers — like those from major cloud providers AWS, Google Cloud, Microsoft Azure, etc.
Dataprobe manufactures power management products that assist businesses in monitoring and controlling their infrastructure. Their iBoot PDU allows administrators to remotely manage the power supply to their devices and equipment via a simple and easy-to-use web application. Dataprobe has thousands of devices across numerous industries — from deployments in data centers, travel and transportation infrastructure, financial institutions, smart city IoT installations, and government agencies.
The team found four major vulnerabilities in CyberPower’s DCIM and five critical vulnerabilities in the Dataprobe’s iBoot PDU:

  • CyberPower DCIM:
    • CVE-2023-3264: Use of Hard-coded Credentials (CVSS 6.7)
    • CVE-2023-3265: Improper Neutralization of Escape, Meta, or Control Sequences (Auth Bypass; CVSS 7.2)
    • CVE-2023-3266: Improperly Implemented Security Check for Standard (Auth Bypass; CVSS 7.5)
    • CVE-2023-3267: OS Command Injection (Authenticated RCE; CVSS 7.5)
  • Dataprobe iBoot PDU:
    • CVE-2023-3259: Deserialization of Untrusted Data (Auth Bypass; CVSS 9.8)
    • CVE-2023-3260: OS Command Injection (Authenticated RCE; CVSS 7.2)
    • CVE-2023-3261: Buffer Overflow (DOS; CVSS 7.5)
    • CVE-2023-3262: Use of Hard-coded Credentials (CVSS 6.7)
    • CVE-2023-3263: Authentication Bypass by Alternate Name (Auth Bypass; CVSS 7.5)

“In a world growing ever-reliant on massive amounts of data for business operations, critical infrastructure, and basic internet activities, major vulnerabilities in the data centers making all this possible is a large risk to daily society. Vulnerabilities that enable cybercriminals to slowly infect entire data center deployments to steal key data and information or utilize compromised resources to initiate attacks at a global scale could be leveraged for massive damage. The threats and risks to both consumers and enterprises is high,” commented Sam Quinn, Senior Security Researcher and Jesse Chick, Vulnerability Researcher at the Trellix Advanced Research Center.
Below are some examples of the level of damage a malicious threat actor could do when utilizing exploits of this level across numerous data centers:

  • Power Off: Through access to these power management systems, even the simple act of cutting power to devices connected to a PDU would be significant. Websites, business applications, consumer technologies, and critical infrastructure deployments all rely on the availability of these data centers to operate. A threat actor could cause significant disruption for days at a time with the simple “flip of a switch” in dozens of compromised data centers.
  • Malware at Scale: Using these platforms to create a backdoor on the data center equipment provides bad actors a foothold to compromise a huge number of systems and devices. Some data centers host thousands of servers and connect to hundreds of various business applications. Malicious attackers could slowly compromise both the data center and the business networks connected to it.
  • Digital Espionage: In addition to the previously mentioned malicious activities one would expect of cybercriminals, APTs and nation-state backed threat actors could leverage these exploits to conduct cyberespionage attacks.

Recommendation 

Both Dataprobe and CyberPower have released fixes for these vulnerabilities with CyberPower DCIM version 2.6.9 of their PowerPanel Enterprise software and the latest 1.44.08042023 version of the Dataprobe iBoot PDU firmware. Trellix strongly urges all potentially impacted customers to download and install these patches immediately.
In addition to the official patches, Trellix would suggest taking additional steps for any devices or platforms potentially exposed to 0-day exploitation by these vulnerable products:

  • Ensure that your PowerPanel Enterprise or iBoot PDU are not exposed to the wider Internet. Each should be reachable only from within your organization’s secure intranet.
    • In the case of the iBoot PDU, Trellix suggests disabling remote access via Dataprobe’s cloud service as an added precaution.
  • Modify the passwords associated with all user accounts and revoke any sensitive information stored on both appliances that may have been leaked.
  • Update to the latest version of PowerPanel Enterprise or install the latest firmware for the iBoot PDU and subscribe to the relevant vendor’s security update notifications.
    • Although this measure in and of itself will not reduce risk of attack via the vulnerabilities described in this document, updating all your software to the latest and greatest version promptly is the best practice for ensuring your window of exposure is as short as possible in this and future cases.

“The devices and software platforms that service data centers must remain secure and updated, and the vendors producing this hardware and software have processes in place for quick and efficient response following vulnerability disclosures,” added Quinn and Chick. “We applaud both CyberPower and Dataprobe for their willingness and expediency in working with our team following the discovery of these vulnerabilities. Their responsiveness in creating protections for these vulnerabilities and releasing a patch for their customers shows true organizational maturity and drive to improve security across the entire industry.”

Continue Reading

News

GFH Partners Manrre REIT (CEIC) PLC and Palmon Group unveil new temperature-controlled chemical warehouse in JAFZA

Published

on

GFH Partners Manrre REIT (CEIC) PLC (“Manrre” or “the Fund”), managed by GFH Partners Ltd. (“GFH Partners”),  together with its development manager Palmon Group FZCO (“Palmon Group”), today announced the opening of a specialised temperature-controlled chemical warehouse in Jebel Ali Free Zone (Jafza), further expanding the Fund’s Grade A logistics portfolio.

The inauguration ceremony was held in the presence of Mr Abdulla Bin Damithan, CEO and Managing Director, DP World GC, alongside senior officials and dignitaries from Jebel Ali Free Zone, GFH Partners, and Palmon Group.

Purpose-built and developed by Palmon Group to meet stringent international safety and compliance standards, the new facility reflects the rising regional demand for certified chemical storage infrastructure that supports manufacturing, energy, industrial services, and third-party logistics. The warehouse is situated on a 180,000sq ft plot with a built-up area of 112,000 sq ft, divided into three temperature-controlled chambers that reach a maximum height of 13 metres. The warehouse has been designed with advanced Early Suppression Fast Response (ESFR), and in-rack sprinkler systems to ensure safety and resilience across all operations.

The facility’s layout allows storage of a diverse range of hazard-classified chemicals. One chamber is configured for UN Class 3 and 4 chemicals, a second accommodates UN Class 5 chemicals, while the third has been developed for UN Class 6, 8, 9 and non-regulated materials. The warehouse offers capacity for 17,400 pallets and includes nine loading docks and three loading bays. The office space has been intentionally limited to three percent of the total built-up area, maximising operational efficiency and warehouse utility.

Speaking on the launch, Kunal Lahori, CEO of Palmon Group and Board Member of Manrre, said: “This new facility brings together precision engineering, regulatory compliance, and long-term value creation. Specialised chemical storage requires a high degree of control and risk management, and we have developed this warehouse to meet those expectations while offering flexibility and scalability for tenants. As one of the earliest developers in Jafza, Palmon Group remains committed to supporting the UAE’s logistics and industrial growth.”

Mohamed Ali, Head of GCC at GFH Partners, said: “The opening of this warehouse marks another important milestone in the expansion of the GFH Partners Manrre REIT portfolio, particularly in mission-critical industrial and logistics assets that serve high-growth sectors. The UAE continues to see strong demand for specialised storage solutions, and this facility reinforces our strategy to develop resilient, future-ready assets that deliver long-term value for our investors.”

The logistics hub is now fully operational and is leased to Safe Logistics. The new facility is expected to play a significant role in strengthening regulated supply chains and supporting Dubai’s position as one of the region’s foremost logistics and industrial hubs.

Continue Reading

News

Big Ticket joins DP World ILT20 Season 4 as Official Partner

Published

on

A professional cricket player for the Desert Vipers in mid-swing during a match. The batsman is wearing a dark green and black patterned jersey with red accents, a red helmet, and black protective leg pads. He is holding a wooden cricket bat high in a follow-through motion after playing a shot. The background shows a crowded stadium with purple and blue seating and a "DP World" branded wicket.

Big Ticket, the largest and longest-running guaranteed raffle draw in the Middle East (known for cash prizes, dream luxury cars, gold bars and coins) has joined the DP World International League T20 Season 4 as an Official Partner.

In recent years, Big Ticket has become more than just a raffle, it has gained the reputation of being a brand built around rewarding dreams and celebrating ambition, growing into one of the region’s largest and one of the most anticipated monthly draws in the UAE.

DP World ILT20 – the 34-match cricketing extravaganza – the biggest T20 tournament in the region featuring some of the most renowned global cricket stars is currently being played at the Dubai International Stadium, Zayed Cricket Stadium, Abu Dhabi and Sharjah Cricket Stadium.

A cricket player from the Abu Dhabi Knight Riders standing at the crease, ready to receive a ball. The player is dressed in a purple and gold uniform with matching gold-colored leg pads and a gold helmet. He holds the bat upward in a standard batting stance. The stadium background features blue seats, a "UAE Cricket" sign, and another player in an orange uniform in the distance.

DP World ILT20 Head of Partnerships Ishan Chopra: “We are delighted to welcome a UAE born raffle giant like Big Ticket as an Official Partner of the DP World ILT20. Their legacy of helping dreams come true aligns perfectly with our vision of delivering unforgettable, fan-first experiences across the league. This partnership strengthens our commitment to creating moments of excitement both on and off the field, and we look forward to elevating Season 4 together. With a household name like Big Ticket on board, we are confident of unlocking even more opportunities for fans to engage, celebrate and go All In for Cricket.”

Meanwhile, DP World ILT20 match tickets across all categories are available for the remaining tournament matches. Various spectator stand tickets start at AED 20 and hospitality packages start from AED 325. Fans can also book the new Sixes Lounge experience for AED 395, which includes unlimited food and beverages. Tickets can be purchased by visiting tickets.ilt20.ae or Virgin Megastores.

Continue Reading

News

The Maritime Standard Awards 2025 winners list showcases high levels of innovation and operational excellence across the maritime sector

Published

on


The maritime sector’s leading awards event, The Maritime Standard (TMS) Awards 2025, has announced this year’s winners, honoring outstanding companies and industry leaders from across the Middle East and Indian Subcontinent. The Awards showcased achievement and innovation in 25 categories covering shipping, logistics, ship repair, offshore services, marine technology and related sectors, as well as a series of special awards for individual achievement. The prestigious event took place at Atlantis The Palm, Dubai on October 29th, attracting over 1000 senior executives, decision-makers and industry leaders, from the region, and across the globe.

Held under the patronage of H.H. Sheikh Ahmed bin Saeed Al Maktoum, President of the Dubai Civil Aviation Authority, Chairman of Dubai Airports, and Chairman and Chief Executive of Emirates Airline and Group, the event recognised organisations and individuals for setting new standards in operational excellence and leadership in the sector amid significant shifts in the industry, including decarbonisation, digitalization, and a renewed emphasis on supply chain resilience. From clean-fuel projects and AI-powered port operations to international collaborations that boost trade efficiency, the 2025 Awards showcased the industry’s progress in turning goals into tangible outcomes.

The evening was hosted by Yalda Hakim, a renowned international correspondent and documentary filmmaker, whose engaging presence added distinction to the occasion. The keynote address was delivered by Captain Abdulkareem Al Masabi, CEO of ADNOC Logistics and Services, who shared valuable insights on the evolving maritime landscape and the UAE’s leadership in advancing sustainable and innovative practices across the sector.

Clive Woodbridge, Editor of The Maritime Standard and Chairman of the Judging Panel, stated, “This year’s competition was exceptionally tough, and we received an unprecedented number of entries across all categories. Each finalist demonstrated remarkable achievements and operational standards over the past year, which underlines the significant advances that continue to be made in the regional maritime sector.”

A rigorous assessment process was conducted as part of the award selections, and this was supervised by an independent panel of distinguished judges that included some of the most prominent names in the maritime industry.

Trevor Pereira, Managing Director of The Maritime Standard, commented, “These Awards are not just about celebrating success, but also about encouraging excellence. This year’s event recognised innovative concepts, exciting new initiatives, and outstanding performance standards. As the region continues to expand its maritime infrastructure and digital port systems, with significant developments across the Middle East and the Indian Subcontinent, events like The Maritime Standard Awards play a key role in reinforcing its position as a global leader in shipping and maritime.”

 Reaction from the individual winners on the night of October 29th was highly appreciative. Captain Mohamed Al Ali, Senior Vice President, Operations (Offshore Logistics), at ADNOC L&S, who received the Outstanding Achievement Award, added: “It was one of the greatest honours of my professional career to receive this Award. It really means a lot to me to have TMS recognise the years of dedication and hard work.”

Tony Dagher, the Founder and Managing Director of TMC Shipping Group was the recipient of the Young Person in Shipping and was similarly honoured. He said: “I have been fortunate to have had great support from many people during my journey in shipping, and to have a fantastic team around me now. This Award is as much for them as it is for me.

Over the past 12 years The Maritime Standard Awards has consolidated its standing as one of the most prominent annual gatherings within the global maritime calendar, gaining worldwide recognition for recognising excellence and promoting a more resilient and sustainable maritime future.

Continue Reading

Trending

Copyright © 2023 | The Integrator