Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the network
Impact
OS command injection over the network on the DCIM appliance - same blast radius as the path traversal above, reached by a different route. An attacker running commands on DCE inherits its trust relationship with every piece of power and cooling gear at the site.
Who can reach it
Remote, over the network to the DCE appliance.
What to do
Upgrade to DCE v7.9.0 or later and rotate all stored device credentials. If the appliance was reachable from an untrusted network, rebuild it - DCE keeps polling credentials in a form an attacker with shell can read.
References
Related entries
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCVE-2021-22794 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
- Ceph Manager (volumes plugin): Owner of one CephFS share can read/write any share or the entire file systemCVE-2022-0670 · Ceph Manager (volumes plugin)Critical
- Zabbix: Unverified user login in session data (SAML SSO enabled)CVE-2022-23131 · ZabbixCritical
- FlyteConsole (cors_proxy endpoint): FlyteConsole's cors_proxy forwards attacker-chosen URLs, so anyone who reaches theCVE-2022-24856 · FlyteConsole (cors_proxy endpoint)Critical
- CyberPower PowerPanel Business - default.cmd file upload: Unrestricted upload of a dangerous file type into default.cmdCVE-2023-25132 · CyberPower PowerPanel Business - default.cmd file uploadCritical
- HAProxy (before 2.7.3): HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to makeCVE-2023-25725 · HAProxy (before 2.7.3)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.