GPU VulnDB

Database/Firmware, BMC & network fabric

Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPS: Path traversal lets

CVE-2023-6032Firmware, BMC & network fabricSEVD-2023-318-03curated

Impact

Path traversal lets an attacker enumerate and download files from the management card on a large three-phase UPS - the class of unit that sits between utility power and an entire GPU hall, not a single rack. What leaks is configuration and credential material for the power estate. Treat this as reconnaissance that precedes a physical availability attack rather than as a data-loss event in itself.

Who can reach it

Anyone who can reach the NMC's HTTPS interface. Galaxy-class UPS management cards live on the facility network, which in a leased colo is usually the landlord's network, not yours.

What to do

Firmware update to the card, per SEVD-2023-318-03. Non-disruptive to the load, but on a leased site you may not own the equipment - in that case the real remediation is contractual: require the landlord to evidence the patch level of every UPS management card that feeds your halls, and require the facility network to be segmented from anything you run.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.