Database/Firmware, BMC & network fabric

Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPS: Path traversal lets
Impact
Path traversal lets an attacker enumerate and download files from the management card on a large three-phase UPS - the class of unit that sits between utility power and an entire GPU hall, not a single rack. What leaks is configuration and credential material for the power estate. Treat this as reconnaissance that precedes a physical availability attack rather than as a data-loss event in itself.
Who can reach it
Anyone who can reach the NMC's HTTPS interface. Galaxy-class UPS management cards live on the facility network, which in a leased colo is usually the landlord's network, not yours.
What to do
Firmware update to the card, per SEVD-2023-318-03. Non-disruptive to the load, but on a leased site you may not own the equipment - in that case the real remediation is contractual: require the landlord to evidence the patch level of every UPS management card that feeds your halls, and require the facility network to be segmented from anything you run.
References
Related entries
- Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race): A time-of-check/time-of-use race in BIOS givesCVE-2024-0171 · Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race)Medium
- Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is notCVE-2024-27891 · Arista EOS (MACsec with egress ACLs)Medium
- Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privilegedCVE-2024-31157 · Intel UEFI firmware (OutOfBandXML module)Medium
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationCVE-2024-38303 · Dell PowerEdge 14G Intel BIOS (improper input validation)Medium
- Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset): IHISI function 0x49 restores certain UEFICVE-2024-39707 · Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset)Medium
- GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-freeCVE-2024-45783 · GRUB2 (HFS+ filesystem parser)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.