Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert before 7.4.0: Passwords held in cleartext in RAM on the DCIM
Impact
Passwords held in cleartext in RAM on the DCIM appliance, recoverable remotely. Included here because it is the earliest entry in a seven-year pattern: DCE has repeatedly failed to protect the device credentials it must hold, and any operator running an old DCE build should assume the facility credential set is compromised rather than assume otherwise.
Who can reach it
Remote, per the advisory; unspecified vectors, but the practical read is that a foothold on or near the appliance yields the credentials.
What to do
Upgrade to 7.4.0 or later - though anyone still on a pre-7.4 build has far larger problems from the 2021-2024 RCEs above. Rotate all device credentials.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.