Database/Control plane, storage & DevOps

Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - device credential endpoints: Incorrect
Impact
Incorrect authorisation lets a low-privileged DCE user read device credentials from endpoints that were never meant to expose them. The read-only NOC account you gave a monitoring contractor becomes the credential set for the entire power and cooling estate.
Who can reach it
Any low-privileged authenticated user on the DCE appliance - including accounts issued to third-party monitoring and maintenance vendors.
What to do
Upgrade past V7.9.2. Then rotate device credentials and audit who holds DCE accounts. In most operators this audit is the finding: DCE accounts accumulate for vendors, integrators and former staff, and nobody owns the list.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.