GPU VulnDB

Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert before 7.4.0: Passwords held in cleartext in RAM on the DCIM

CVE-2017-8371Control plane, storage & DevOpscurated

Impact

Passwords held in cleartext in RAM on the DCIM appliance, recoverable remotely. Included here because it is the earliest entry in a seven-year pattern: DCE has repeatedly failed to protect the device credentials it must hold, and any operator running an old DCE build should assume the facility credential set is compromised rather than assume otherwise.

Who can reach it

Remote, per the advisory; unspecified vectors, but the practical read is that a foothold on or near the appliance yields the credentials.

What to do

Upgrade to 7.4.0 or later - though anyone still on a pre-7.4 build has far larger problems from the 2021-2024 RCEs above. Rotate all device credentials.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.