Database/Firmware, BMC & network fabric

Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web server
Impact
The card's integrated web server has a broken authorization check, letting a remote attacker get full administrative access to the UPS/STS management interface without valid credentials — including whatever load-shedding and shutdown controls that UPS exposes.
Who can reach it
Remote, over the network, to the card's web server on port 80/443 — no valid credentials required to bypass the authorization check.
What to do
Firmware flash of the Network Management Card required; Schneider's SEVD-2018-074-01 advisory has the fixed build. Roll out per card — each flash briefly drops remote monitoring/management of that UPS (the UPS itself keeps powering its load through the flash).
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.