The Vertiv Avocent Universal Management Gateway Model UMG-4000 is a data center management appliance. The web interface of the UMG-4000 is vulnerable to command injection, stored cross-site scripting (XSS), and reflected XSS, which may allow an authenticated attacker with administrative privileges to remotely execute arbitrary code.
The Vertiv Avocent UMG-4000 contains multiple vulnerabilities that could allow an authenticated attacker with administrative privileges to remotely execute arbitrary code. The web interface does not sanitize input provided from the remote client, making it vulnerable to command injection, stored cross-site scripting, and reflected cross-site scripting.
CVE-2019-9507 - CWE-95
An authenticated remote attacker could inject arbitrary scripts or persistently store malicious scripts on the web server that could be used to collect and exfiltrate sensitive information.
Apply an update
- https://www.vertiv.com/globalassets/documents/firmware/universal-management-gateway-release-notes-v126.96.36.199_vertiv_update.pdf https://www.vertiv.com/en-us/support/software-download/it-management/avocent-universal-management-gateway-appliance--software-downloads/
This document was written by Laurie Tyzenhaus.