Database/Control plane, storage & DevOps
Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated user
Impact
Improper neutralisation (injection) in Data Center Manager lets an authenticated user with adjacent access escalate privilege on the management plane.
Who can reach it
Authenticated user with network adjacency to the DCM server.
What to do
Upgrade the Intel Data Center Manager software. This is a management-plane application, so the update is an application upgrade and service restart - no node drain, no firmware, no reboot of managed hosts. The real work is deciding what DCM is allowed to reach: it holds credentials for platform power and telemetry across the fleet, so its network exposure matters more than its version. Upgrade to 4.1 or later.
References
Related entries
- Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attackerCVE-2022-23182 · Intel Data Center ManagerHigh
- Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwordsCVE-2022-32519 · Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storageHigh
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorCVE-2024-39368 · Intel Neural Compressor (SQL injection)High
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesCVE-2024-45766 · Dell OpenManage Enterprise (code injection)High
- Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silentlyCVE-2025-68803 · Linux NFS server (nfsd, NFSv4 file creation ACL)High
- Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesCVE-2025-7766 · Lantronix Provisioning ManagerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.