GPU VulnDB

Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injection

CVE-2023-25549Control plane, storage & DevOpsSEVD-2023-101-04curated

Impact

Code injection through a parameter of the DCE network-settings endpoint gives remote code execution on the DCIM appliance. Same outcome as the other DCE RCEs: control of the facility-layer aggregation point.

Who can reach it

Authenticated remote access to the DCE administrative interface.

What to do

Upgrade past V7.9.2 (SEVD-2023-101-04 covers this whole batch - CVE-2023-25547 through -25555 - so patch once). Rotate stored device credentials afterwards.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.