Database/Firmware, BMC & network fabric

APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRow
Impact
The card's troubleshooting archive — a diagnostic bundle that can contain configuration and log details — can be pulled off the device by someone who shouldn't have access to it, giving an attacker reconnaissance data useful for planning further attacks on that power/cooling unit.
Who can reach it
Network access to the card's web interface; the advisory describes this as an information-exposure issue reachable without full administrative rights.
What to do
Firmware upgrade per Schneider's SEVD-2021-313-03 advisory (fixed AOS versions vary by card generation — NMC2 vs NMC3). This spans a very wide product line (UPS, rack PDUs, cooling, NetBotz), so treat it as a fleet-wide inventory-and-patch exercise rather than a one-off fix.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.