Vertiv Liebert IS-UNITY-DP and RDU101 UPS network cards: two critical vulnerabilities disclosed by Claroty Team82
CVSS 9.8 x2 (CVE-2025-46412, CVE-2025-41426)observed
| Value kind | observed — Reported measurements, counts, and specifications keep the precision and scope stated by their source; an exact specification is not treated as a range. |
|---|---|
| Scope | Disclosed and patched; chaining gives unauthenticated remote code execution on the UPS card. Named data-center equipment, not generic BMS. |
| As of | 2026-06-09 |
| Source | Claroty Team82, "Attacking UPS Network Cards to Take Down Data Centers", 2026-06-09; states CVE-2025-46412 (authentication bypass, CVSS v3 9.8) and CVE-2025-41426 (stack-based buffer overflow, CVSS v3 9.8) in the Liebert IS-UNITY-DP and RDU101 cards; fixes IS-UNITY v8.4.3.1_00160 and RDU101 v1.9.1.2_0000001. · Research post CVE summary and remediation section. |
| Review | checking…review by 2027-03-08 · standard cadence |
| Recorded changes | none recorded |
| Claim id | p2b-11-10-vertiv-ups-card-cves |
Where the guide uses it
Not quoted in a chapter yet; it is kept in the curated register.
← Full numbers register — every date-stamped figure in the guide, with revision history.