GPU VulnDB

Database/Firmware, BMC & network fabric

Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web server

CVE-2018-7243Firmware, BMC & network fabricSEVD-2018-074-01curated

Impact

The card's integrated web server has a broken authorization check, letting a remote attacker get full administrative access to the UPS/STS management interface without valid credentials — including whatever load-shedding and shutdown controls that UPS exposes.

Who can reach it

Remote, over the network, to the card's web server on port 80/443 — no valid credentials required to bypass the authorization check.

What to do

Firmware flash of the Network Management Card required; Schneider's SEVD-2018-074-01 advisory has the fixed build. Roll out per card — each flash briefly drops remote monitoring/management of that UPS (the UPS itself keeps powering its load through the flash).

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.