Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert before 7.4.0: Passwords held in cleartext in RAM on the DCIM
Impact
Passwords held in cleartext in RAM on the DCIM appliance, recoverable remotely. Included here because it is the earliest entry in a seven-year pattern: DCE has repeatedly failed to protect the device credentials it must hold, and any operator running an old DCE build should assume the facility credential set is compromised rather than assume otherwise.
Who can reach it
Remote, per the advisory; unspecified vectors, but the practical read is that a foothold on or near the appliance yields the credentials.
What to do
Upgrade to 7.4.0 or later - though anyone still on a pre-7.4 build has far larger problems from the 2021-2024 RCEs above. Rotate all device credentials.
References
Related entries
- RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)CVE-2020-12355 · RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)Medium
- Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMeCVE-2020-13799 · Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMe - multi-vendor…Medium
- IBM Spectrum Scale Container Native Storage Access (CSI volume handling): Anyone who can create a pod plus a PV/PVCCVE-2022-40607 · IBM Spectrum Scale Container Native Storage Access (CSI volume handling)Medium
- AMD - overlap between segmented reverse map table (RMP) and SMM memory: Improper handling of overlap between theCVE-2025-0012 · AMD - overlap between segmented reverse map table (RMP) and SMM memoryMedium
- Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsCVE-2025-14304 · Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsMedium
- Argo CD: Secret values exposed in error messages and the diff view when an invalid Secret is syncedCVE-2025-23216 · Argo CDMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.