Database/Control plane, storage & DevOps

Schneider Electric Data Center Expert 7.5.0 and earlier - zip upload: A crafted zip uploaded through the DCE UI can
Impact
A crafted zip uploaded through the DCE UI can path-traverse out of its intended directory and write arbitrary files on the appliance. The exploit path is social as much as technical: an authenticated operator is tricked into uploading a file that looks like a normal DCIM import.
Who can reach it
An authenticated DCE user performing what looks like a routine upload of a supplied file.
What to do
Upgrade past 7.5.0. Operationally, the lesson generalises to every DCIM: treat imported bundles, device definition packs and 'helpful' vendor-supplied files as untrusted input.
References
Related entries
- CyberPower PowerPanel Business Edition 3.4.0 Agent/Center: Cross-site request forgery across all forms in the webCVE-2019-13071 · CyberPower PowerPanel Business Edition 3.4.0 Agent/CenterHigh
- Cisco Nexus 9000 ACI Mode (LLDP subsystem): A buffer overflow in the LLDP subsystem of Nexus 9000 switches in ACI modeCVE-2019-1901 · Cisco Nexus 9000 ACI Mode (LLDP subsystem)High
- IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runsCVE-2019-4715 · IBM Spectrum Scale management GUIHigh
- AMD ATI atillk64.sys - physical memory mapping driver: The AMD ATI atillk64.sys driver exposes routines that mapCVE-2020-12138 · AMD ATI atillk64.sys - physical memory mapping driverHigh
- Intel Data Center Manager Console: Improper input validation in the DCM Console lets an authenticated user escalateCVE-2020-12347 · Intel Data Center Manager ConsoleHigh
- Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the managementCVE-2020-17389 · Marvell QConvergeConsole (QLogic adapter management)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.