The Vertiv Avocent Universal Management Gateway Model UMG-4000 is a data center management appliance. The web interface of the UMG-4000 is vulnerable to command injection, stored cross-site scripting (XSS), and reflected XSS, which may allow an authenticated attacker with administrative privileges to remotely execute arbitrary code.
The Vertiv Avocent UMG-4000 contains multiple vulnerabilities that could allow an authenticated attacker with administrative privileges to remotely execute arbitrary code. The web interface does not sanitize input provided from the remote client, making it vulnerable to command injection, stored cross-site scripting, and reflected cross-site scripting.
CVE-2019-9507 - CWE-95
An authenticated remote attacker could inject arbitrary scripts or persistently store malicious scripts on the web server that could be used to collect and exfiltrate sensitive information.
Apply an update
Notified: February 28, 2019 Updated: March 23, 2020
Statement Date: January 07, 2020
Vertiv (Avocent) has addressed these issues.
Non-Trellis customers are encouraged to install Universal Management Gateway firmware version 188.8.131.52 or higher to address these vulnerabilities, located here.
Trellis users of the Universal Management Gateway running firmware version 184.108.40.206 that are operating Trellis versions 5.0.2 through 5.0.6 should install the update patch located here.
Trellis users of the Universal Management Gateway that are operating Trellis versions 5.0.6 and later should install Universal Gateway firmware version 220.127.116.11 located here.
We are not aware of further vendor information regarding this vulnerability.
- https://www.vertiv.com/globalassets/documents/firmware/universal-management-gateway-release-notes-v18.104.22.168_vertiv_update.pdf https://www.vertiv.com/en-us/support/software-download/it-management/avocent-universal-management-gateway-appliance--software-downloads/
This document was written by Laurie Tyzenhaus.
|CVE IDs:||CVE-2019-9507, CVE-2019-9508, CVE-2019-9509|
|Date First Published:||2020-03-30|
|Date Last Updated:||2020-03-30 17:38 UTC|