GPU VulnDB

Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - device credential endpoints: Incorrect

CVE-2023-25548Control plane, storage & DevOpsSEVD-2023-101-04curated

Impact

Incorrect authorisation lets a low-privileged DCE user read device credentials from endpoints that were never meant to expose them. The read-only NOC account you gave a monitoring contractor becomes the credential set for the entire power and cooling estate.

Who can reach it

Any low-privileged authenticated user on the DCE appliance - including accounts issued to third-party monitoring and maintenance vendors.

What to do

Upgrade past V7.9.2. Then rotate device credentials and audit who holds DCE accounts. In most operators this audit is the finding: DCE accounts accumulate for vendors, integrators and former staff, and nobody owns the list.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.