Vertiv Liebert RDU101 and UNITY
Vertiv Liebert RDU101 versions 1.9.0.0 and earlier, and IS-UNITY versions 8.4.1.0 and earlier, contain vulnerabilities (CWE-288 insufficient authentication, CWE-121 stack-based buffer overflow) that allow remote code execution or denial of service. An unauthenticated attacker with network access can exploit these flaws to run arbitrary commands on the device or crash it. IS-UNITY is deployed in building management systems including HVAC control, power monitoring, and environmental management across data centers, hospitals, and critical infrastructure.
- Network access to the RDU101 or IS-UNITY device on its management port (typically accessible from network)
- No authentication or valid credentials required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/0e374885-b1b2-41fb-8439-23abea59df39Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.