Database/Control plane, storage & DevOps

Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserialization: Unsafe deserialization of data
CVE-2022-32521Control plane, storage & DevOpsSEVD-2023-010-06curated
Impact
Unsafe deserialization of data posted to the web server yields remote code execution on the DCIM appliance. Standard deserialization bug, non-standard consequence: the host it lands on controls the power and cooling telemetry and credentials for the building.
Who can reach it
Remote, by posting crafted serialized data to the DCE web server.
What to do
Upgrade to DCE v7.9.0 or later. Rotate stored credentials. Restrict who can reach the DCE web interface to a management jump host.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.