Database/Firmware, BMC & network fabric

Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabled
Impact
On default settings without SSL enabled, repeatedly requesting the card's Access Control page leaks the administrative account credentials in plaintext to anyone who can sniff the traffic — handing over full UPS management access.
Who can reach it
Requires network position to observe traffic to/from the card's web server (or direct access to the unencrypted HTTP endpoint) while an admin session touches the Access Control page.
What to do
Firmware flash to the fixed build, and as an immediate compensating step, force SSL/TLS on for the card's web interface rather than leaving it on plaintext HTTP. Same per-card rollout as the authorization-bypass companion CVE — do both in the same maintenance pass.
References
Related entries
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web serverCVE-2018-7243 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentialsCVE-2018-7820 · APC UPS Network Management Card 2 (AOS 6.5.6)Critical
- Intel CSME 12.0.0-12.0.34: A buffer overflow in a CSME subsystem reachable over the network by an unauthenticatedCVE-2019-0153 · Intel CSME 12.0.0-12.0.34Critical
- Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: HeapCVE-2019-11171 · Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network servicesCritical
- Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reachCVE-2019-13553 · Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4)Critical
- Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCVE-2019-3705 · Dell iDRAC7/8Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.