Raritan PowerIQ 4.1 / 4.2 / 4.3 Code Execution

Raritan PowerIQ versions 4.1, 4.2, and 4.3 ship with a Rails 2 web interface with a hardcoded session secret. This can be used to achieve unauthenticated remote code execution as the nginx user on vulnerable systems.

Leave a Reply