Overview
The Vertiv Avocent Universal Management Gateway Model UMG-4000 is a data center management appliance. The web interface of the UMG-4000 is vulnerable to command injection, stored cross-site scripting (XSS), and reflected XSS, which may allow an authenticated attacker with administrative privileges to remotely execute arbitrary code.
Description
The Vertiv Avocent UMG-4000 contains multiple vulnerabilities that could allow an authenticated attacker with administrative privileges to remotely execute arbitrary code. The web interface does not sanitize input provided from the remote client, making it vulnerable to command injection, stored cross-site scripting, and reflected cross-site scripting. CVE-2019-9507 - CWE-95 |
Impact
An authenticated remote attacker could inject arbitrary scripts or persistently store malicious scripts on the web server that could be used to collect and exfiltrate sensitive information. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 8.5 | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Temporal | 6.7 | E:POC/RL:OF/RC:C |
Environmental | 6.7 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- https://www.vertiv.com/globalassets/documents/firmware/universal-management-gateway-release-notes-v4.3.0.23_vertiv_update.pdf https://www.vertiv.com/en-us/support/software-download/it-management/avocent-universal-management-gateway-appliance--software-downloads/
- https://www.vertiv.com/en-us/support/software-download/software/trellis-enterprise-and-quick-start-solutions-software-downloads/
- https://cwe.mitre.org/data/definitions/95.html
- https://cwe.mitre.org/data/definitions/79.html
- https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)#Stored_and_Reflected_XSS_Attacks
- https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html
Acknowledgements
This document was written by Laurie Tyzenhaus.
Other Information
CVE IDs: | CVE-2019-9507, CVE-2019-9508, CVE-2019-9509 |
Date Public: | 2019-04-12 |
Date First Published: | 2020-03-30 |
Date Last Updated: | 2020-03-30 17:38 UTC |
Document Revision: | 94 |