Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injection
CVSS 7.2CVE-2023-25549Control plane, storage & DevOpsSEVD-2023-101-04curated
Impact
Code injection through a parameter of the DCE network-settings endpoint gives remote code execution on the DCIM appliance. Same outcome as the other DCE RCEs: control of the facility-layer aggregation point.
Who can reach it
Authenticated remote access to the DCE administrative interface.
What to do
Upgrade past V7.9.2 (SEVD-2023-101-04 covers this whole batch - CVE-2023-25547 through -25555 - so patch once). Rotate stored device credentials afterwards.
References
Related entries
- Lenovo ThinkSystem SMM / SMM2 and FPC (command injection): An authenticated user with elevated privileges executesCVE-2024-2659 · Lenovo ThinkSystem SMM / SMM2 and FPC (command injection)High
- Schneider Electric Data Center Expert - upgrade bundle signature verification: Improper cryptographic signatureCVE-2024-8531 · Schneider Electric Data Center Expert - upgrade bundle signature verificationHigh
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyCVE-2024-9180 · HashiCorp VaultHigh
- Palo Alto PAN-OS: Admin with mgmt-interface access performs firewall actions as rootCVE-2024-9474 · Palo Alto PAN-OSHigh
- Volcano (scheduler, Elastic service and extender plugin response handling): The scheduler reads unbounded responsesCVE-2025-32777 · Volcano (scheduler, Elastic service and extender plugin response handling)High
- Oracle ZFS Storage Appliance Kit: HTTP-reachable flaw in Block Storage allows full appliance takeoverCVE-2025-62290 · Oracle ZFS Storage Appliance Kit 8.8 (Block Storage component)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.