GPU VulnDB

Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code execution

CVE-2021-22794Control plane, storage & DevOpsSEVD-2022-095-01curated

Impact

Path traversal to remote code execution on the DCIM appliance. DCE is the aggregation point for a site's entire power and cooling estate - it holds working credentials for every UPS, PDU, NMC, CRAC and sensor it polls. Compromise here is not one device; it is the keys to the whole facility layer, and from there PHYSICAL control of power and cooling.

Who can reach it

Network access to the DCE appliance. DCE typically sits on the facility management network with broad reachability by design, since it must poll everything.

What to do

Upgrade DCE to v7.9.0 or later. Appliance upgrade with a service restart - hours, not a power maintenance window. Afterwards, rotate every device credential DCE stored, because they were all reachable. Long term, DCE should be the most tightly segmented host you run: inbound access from a jump host only, no internet egress.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.