CVE-2025-66237

MEDIUM

DCIM dcTrack - Privilege Escalation

Title source: llm

Description

DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.

Scores

CVSS v3 6.7
EPSS 0.0002
EPSS Percentile 3.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-798
Status draft

Timeline

Published Dec 04, 2025
Tracked Since Feb 18, 2026