Database/Firmware, BMC & network fabric

Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web server
Impact
The card's integrated web server has a broken authorization check, letting a remote attacker get full administrative access to the UPS/STS management interface without valid credentials — including whatever load-shedding and shutdown controls that UPS exposes.
Who can reach it
Remote, over the network, to the card's web server on port 80/443 — no valid credentials required to bypass the authorization check.
What to do
Firmware flash of the Network Management Card required; Schneider's SEVD-2018-074-01 advisory has the fixed build. Roll out per card — each flash briefly drops remote monitoring/management of that UPS (the UPS itself keeps powering its load through the flash).
References
Related entries
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabledCVE-2018-7246 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentialsCVE-2018-7820 · APC UPS Network Management Card 2 (AOS 6.5.6)Critical
- Intel CSME 12.0.0-12.0.34: A buffer overflow in a CSME subsystem reachable over the network by an unauthenticatedCVE-2019-0153 · Intel CSME 12.0.0-12.0.34Critical
- Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: HeapCVE-2019-11171 · Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network servicesCritical
- Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reachCVE-2019-13553 · Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4)Critical
- Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCVE-2019-3705 · Dell iDRAC7/8Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.