Database/Control plane, storage & DevOps

Schneider Electric Data Center Expert - upgrade bundle signature verification: Improper cryptographic signature
Impact
Improper cryptographic signature verification on DCE upgrade bundles: a manipulated bundle can carry arbitrary bash scripts that execute as root. Your patching process becomes the attack. Anyone who can place a bundle in front of the appliance - a compromised mirror, an internal file share, a helpful vendor email - gets root on the system holding the facility's power and cooling credentials.
Who can reach it
Requires getting a crafted upgrade bundle to the appliance. In practice: whoever runs DCE upgrades, or anyone who can tamper with where the bundles are staged.
What to do
Upgrade DCE per SEVD-2024-282-01 to a build that verifies signatures correctly. Until then, treat upgrade bundles as untrusted code: obtain them only over an authenticated channel from the vendor, verify hashes out of band, and stage them somewhere with restricted write access.
References
Related entries
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyCVE-2024-9180 · HashiCorp VaultHigh
- Palo Alto PAN-OS: Admin with mgmt-interface access performs firewall actions as rootCVE-2024-9474 · Palo Alto PAN-OSHigh
- Volcano (scheduler, Elastic service and extender plugin response handling): The scheduler reads unbounded responsesCVE-2025-32777 · Volcano (scheduler, Elastic service and extender plugin response handling)High
- Oracle ZFS Storage Appliance Kit: HTTP-reachable flaw in Block Storage allows full appliance takeoverCVE-2025-62290 · Oracle ZFS Storage Appliance Kit 8.8 (Block Storage component)High
- AMD CPUs - attacker influence over RDSEED entropy: A local attacker can influence the values RDSEED returns, causingCVE-2025-62626 · AMD CPUs - attacker influence over RDSEED entropyHigh
- Dell OpenManage Enterprise: unauthenticated SSRF reaches services on the management networkCVE-2026-54794 · Dell OpenManage Enterprise (web interface)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.