PatchSiren cyber security CVE debrief
CVE-2025-66237 Sunbird CVE debrief
Sunbird DCIM dcTrack and Power IQ platforms contain default and hard-coded credentials that enable administrative database access, privilege escalation, and host command execution. CISA published advisory ICSA-25-338-05 on December 4, 2025, assigning CVSS 3.1 score 6.7 (MEDIUM). The vulnerability requires local access and high privileges to exploit, but successful exploitation yields complete confidentiality, integrity, and availability compromise. Sunbird has released patched versions: dcTrack 9.2.3 and Power IQ 9.2.1. Organizations unable to update immediately should restrict SSH and non-essential port access via IP-based controls and change SSH account passwords at deployment.
- Vendor
- Sunbird
- Product
- DCIM dcTrack
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-04
- Original CVE updated
- 2025-12-04
- Advisory published
- 2025-12-04
- Advisory updated
- 2025-12-04
Who should care
Organizations operating Sunbird DCIM dcTrack or Power IQ data center infrastructure management platforms, particularly those in critical infrastructure sectors with OT/ICS environments. Security teams responsible for industrial control system hardening, database administrators managing dcTrack deployments, and infrastructure teams maintaining Power IQ installations should prioritize patching or implementing interim access controls.
Technical summary
Sunbird DCIM dcTrack and Power IQ platforms ship with default and hard-coded credentials. An attacker with local access and high privileges can use these credentials to administer the database, escalate privileges on the platform, or execute system commands on the underlying host. The vulnerability is rated CVSS 3.1 6.7 (MEDIUM) with local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Sunbird has released dcTrack 9.2.3 and Power IQ 9.2.1 to address this issue. Interim mitigations include IP-based access control restrictions and mandatory SSH password changes at deployment.
Defensive priority
HIGH
Recommended defensive actions
- Update dcTrack to version 9.2.3 or later
- Update Power IQ to version 9.2.1 or later
- If immediate patching is not possible, restrict SSH and non-essential port access using IP-based access controls
- Change passwords for all SSH-based user accounts at deployment time
- Review and harden all default credentials across Sunbird DCIM infrastructure
- Monitor for unauthorized administrative access attempts to database and host systems
Evidence notes
CISA CSAF advisory ICSA-25-338-05 confirms default and hard-coded credentials in dcTrack and Power IQ platforms. CVSS 3.1 vector AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H indicates local attack vector with high privileges required but high impact on CIA triad. Remediation guidance specifies version updates and interim access controls.
Official resources
-
CVE-2025-66237 CVE record
CVE.org
-
CVE-2025-66237 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-12-04