Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the network
Impact
OS command injection over the network on the DCIM appliance - same blast radius as the path traversal above, reached by a different route. An attacker running commands on DCE inherits its trust relationship with every piece of power and cooling gear at the site.
Who can reach it
Remote, over the network to the DCE appliance.
What to do
Upgrade to DCE v7.9.0 or later and rotate all stored device credentials. If the appliance was reachable from an untrusted network, rebuild it - DCE keeps polling credentials in a form an attacker with shell can read.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.