PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66237 Sunbird CVE debrief

Sunbird DCIM dcTrack and Power IQ platforms contain default and hard-coded credentials that enable administrative database access, privilege escalation, and host command execution. CISA published advisory ICSA-25-338-05 on December 4, 2025, assigning CVSS 3.1 score 6.7 (MEDIUM). The vulnerability requires local access and high privileges to exploit, but successful exploitation yields complete confidentiality, integrity, and availability compromise. Sunbird has released patched versions: dcTrack 9.2.3 and Power IQ 9.2.1. Organizations unable to update immediately should restrict SSH and non-essential port access via IP-based controls and change SSH account passwords at deployment.

Vendor
Sunbird
Product
DCIM dcTrack
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-04
Original CVE updated
2025-12-04
Advisory published
2025-12-04
Advisory updated
2025-12-04

Who should care

Organizations operating Sunbird DCIM dcTrack or Power IQ data center infrastructure management platforms, particularly those in critical infrastructure sectors with OT/ICS environments. Security teams responsible for industrial control system hardening, database administrators managing dcTrack deployments, and infrastructure teams maintaining Power IQ installations should prioritize patching or implementing interim access controls.

Technical summary

Sunbird DCIM dcTrack and Power IQ platforms ship with default and hard-coded credentials. An attacker with local access and high privileges can use these credentials to administer the database, escalate privileges on the platform, or execute system commands on the underlying host. The vulnerability is rated CVSS 3.1 6.7 (MEDIUM) with local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Sunbird has released dcTrack 9.2.3 and Power IQ 9.2.1 to address this issue. Interim mitigations include IP-based access control restrictions and mandatory SSH password changes at deployment.

Defensive priority

HIGH

Recommended defensive actions

  • Update dcTrack to version 9.2.3 or later
  • Update Power IQ to version 9.2.1 or later
  • If immediate patching is not possible, restrict SSH and non-essential port access using IP-based access controls
  • Change passwords for all SSH-based user accounts at deployment time
  • Review and harden all default credentials across Sunbird DCIM infrastructure
  • Monitor for unauthorized administrative access attempts to database and host systems

Evidence notes

CISA CSAF advisory ICSA-25-338-05 confirms default and hard-coded credentials in dcTrack and Power IQ platforms. CVSS 3.1 vector AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H indicates local attack vector with high privileges required but high impact on CIA triad. Remediation guidance specifies version updates and interim access controls.

Official resources

2025-12-04