GPU VulnDB

Database/Control plane, storage & DevOps

Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserialization: Unsafe deserialization of data

CVE-2022-32521Control plane, storage & DevOpsSEVD-2023-010-06curated

Impact

Unsafe deserialization of data posted to the web server yields remote code execution on the DCIM appliance. Standard deserialization bug, non-standard consequence: the host it lands on controls the power and cooling telemetry and credentials for the building.

Who can reach it

Remote, by posting crafted serialized data to the DCE web server.

What to do

Upgrade to DCE v7.9.0 or later. Rotate stored credentials. Restrict who can reach the DCE web interface to a management jump host.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.