GPU VulnDB

Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the network

CVE-2021-22795Control plane, storage & DevOpsSEVD-2022-095-01curated

Impact

OS command injection over the network on the DCIM appliance - same blast radius as the path traversal above, reached by a different route. An attacker running commands on DCE inherits its trust relationship with every piece of power and cooling gear at the site.

Who can reach it

Remote, over the network to the DCE appliance.

What to do

Upgrade to DCE v7.9.0 or later and rotate all stored device credentials. If the appliance was reachable from an untrusted network, rebuild it - DCE keeps polling credentials in a form an attacker with shell can read.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.