Database/Control plane, storage & DevOps

Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwords
Impact
DCE stores device passwords in a recoverable format. Every UPS, PDU and cooling controller credential the DCIM system polls with can be recovered by an attacker who reaches the appliance. This is the amplifier that turns any of the other DCE bugs from 'one appliance' into 'the facility'.
Who can reach it
Network access to the DCE instance; recoverable-format storage means no cracking effort is needed once a foothold exists.
What to do
Upgrade to v7.9.0 or later, then rotate every stored credential - the upgrade re-protects new secrets, it does not un-leak old ones. Budget the rotation properly: it means touching every managed device, and on a large site that is the expensive part, not the upgrade.
References
Related entries
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorCVE-2024-39368 · Intel Neural Compressor (SQL injection)High
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesCVE-2024-45766 · Dell OpenManage Enterprise (code injection)High
- Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silentlyCVE-2025-68803 · Linux NFS server (nfsd, NFSv4 file creation ACL)High
- Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesCVE-2025-7766 · Lantronix Provisioning ManagerHigh
- Progress Kemp LoadMaster Multi Tenant: The Multi Tenant product line's REST API doesn't check whether a caller'sCVE-2026-59690 · Progress Kemp LoadMaster Multi TenantHigh
- Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSSCVE-2026-84665 · Jenkins SonarQube Scanner Plugin (dashboard link generation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.