Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - device credential endpoints: Incorrect
Impact
Incorrect authorisation lets a low-privileged DCE user read device credentials from endpoints that were never meant to expose them. The read-only NOC account you gave a monitoring contractor becomes the credential set for the entire power and cooling estate.
Who can reach it
Any low-privileged authenticated user on the DCE appliance - including accounts issued to third-party monitoring and maintenance vendors.
What to do
Upgrade past V7.9.2. Then rotate device credentials and audit who holds DCE accounts. In most operators this audit is the finding: DCE accounts accumulate for vendors, integrators and former staff, and nobody owns the list.
References
Related entries
- MinIO: Windows deployments fail to filter `\`CVE-2023-28433 · MinIOHigh
- MinIO: Crafted request bypasses PostPolicyBucket metadata bucket-name checkCVE-2023-28434 · MinIOHigh
- IBM Storage Scale session management: An authenticated user steals or fixates another user's active session andCVE-2023-38002 · IBM Storage Scale session managementHigh
- A10 Thunder ADC (FileMgmtExport): An authenticated attacker can walk outside the intended export directoryCVE-2023-42130 · A10 Thunder ADC (FileMgmtExport)High
- Linux NVMe-oF (nvmet-tcp): Use-after-free/double-free in nvmet_tcp_free_cryptoCVE-2023-5178 · Linux NVMe-oF (nvmet-tcp)High
- PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)CVE-2024-10979 · PostgreSQLHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.