GPU VulnDB

Database/Control plane, storage & DevOps

Vertiv Avocent UMG-4000 universal management gateway: Every command the UMG-4000's web interface runs executes as root

CVE-2019-9507Control plane, storage & DevOpscurated

Impact

Every command the UMG-4000's web interface runs executes as root on the underlying OS. An admin-authenticated attacker who can inject shell syntax into a web form gets root on the gateway — which sits between the operator and every server it's providing KVM/serial access to.

Who can reach it

Requires an authenticated administrator session on the web interface; the app fails to neutralize shell metacharacters before executing commands.

What to do

Software/firmware upgrade from Vertiv; download the fixed build from Vertiv's Avocent UMG support page and flash each gateway. Since the UMG-4000 is the aggregation point for KVM access to many downstream nodes, schedule the update in a maintenance window and expect KVM sessions through that gateway to drop during the flash.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.