CVE-2025-66237

MEDIUM

DCIM dcTrack - Privilege Escalation

Title source: llm
STIX 2.1

Description

DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.

Scores

CVSS v3 6.7
EPSS 0.0002
EPSS Percentile 5.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (4)
Sunbird/DCIM dcTrack < v9.2.0
Sunbird/DCIM dcTrack 9.2.3
Sunbird/IQ < v9.2.0
Sunbird/IQ 9.2.1
Published Dec 04, 2025
Tracked Since Feb 18, 2026