Database/Control plane, storage & DevOps

Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserialization: Unsafe deserialization of data
CVSS 7.1CVE-2022-32521Control plane, storage & DevOpsSEVD-2023-010-06curated
Impact
Unsafe deserialization of data posted to the web server yields remote code execution on the DCIM appliance. Standard deserialization bug, non-standard consequence: the host it lands on controls the power and cooling telemetry and credentials for the building.
Who can reach it
Remote, by posting crafted serialized data to the DCE web server.
What to do
Upgrade to DCE v7.9.0 or later. Rotate stored credentials. Restrict who can reach the DCE web interface to a management jump host.
References
Related entries
- IBM Storage Scale Container Native Storage Access (namespace boundary): A local attacker can initiate connections fromCVE-2022-41737 · IBM Storage Scale Container Native Storage Access (namespace boundary)High
- SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12): Rowhammer bit flips on DDR5, which had been assumed outCVE-2025-6202 · SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12)High
- AMD Zen 5 RDSEED (16-bit and 32-bit variants): On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far moreCVE-2025-68313 · AMD Zen 5 RDSEED (16-bit and 32-bit variants)High
- Grafana: Auth Proxy cache key collision authenticates a low-privileged user as an administratorCVE-2026-14199 · Grafana Auth Proxy authentication (identity cache key built by concatenation)High
- GitLab EE: missing authorization lets a low-privileged member change restricted project settingsCVE-2026-16494 · GitLab EE (project update endpoint authorization)High
- Grafana: alert rule marked as a server-side expression bypasses datasource query authorizationCVE-2026-17183 · Grafana (alert rule server-side expression datasource authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.