GPU VulnDB

Database/Control plane, storage & DevOps

Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0: TENANT ISOLATION: CC-SG is Raritan's single-pane-of-glass

CVE-2018-20687Control plane, storage & DevOpscurated

Impact

TENANT ISOLATION: CC-SG is Raritan's single-pane-of-glass gateway that brokers KVM and serial console access across a whole fleet of Dominion KX/SX switches. An unauthenticated attacker who reaches its web-services endpoint can send a crafted XML request with a malicious DTD, read arbitrary files off the gateway, or force it to make outbound requests (SSRF) into whatever internal network segments the gateway can reach — which by design is every rack it brokers console access to.

Who can reach it

Fully unauthenticated, remote — a crafted XML request to the CommandCenterWebServices endpoint is enough; no login required.

What to do

Software upgrade to CC-SG 8.0.0 or later. This is a single appliance (or small HA pair) rather than a per-rack device, so the upgrade footprint is small, but treat it as urgent — the gateway sits in front of console/KVM access to the entire managed fleet, so an unauthenticated file-read/SSRF bug there is a direct path toward every rack it manages.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.