GPU VulnDB

Database/Firmware, BMC & network fabric

Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabled

CVE-2018-7246Firmware, BMC & network fabricSEVD-2018-074-01curated

Impact

On default settings without SSL enabled, repeatedly requesting the card's Access Control page leaks the administrative account credentials in plaintext to anyone who can sniff the traffic — handing over full UPS management access.

Who can reach it

Requires network position to observe traffic to/from the card's web server (or direct access to the unencrypted HTTP endpoint) while an admin session touches the Access Control page.

What to do

Firmware flash to the fixed build, and as an immediate compensating step, force SSL/TLS on for the card's web interface rather than leaving it on plaintext HTTP. Same per-card rollout as the authorization-bypass companion CVE — do both in the same maintenance pass.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.