GPU VulnDB

Database/Control plane, storage & DevOps

Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named file

CVE-2019-9508Control plane, storage & DevOpscurated

Impact

An authenticated admin can plant a maliciously named file in the web application that executes JavaScript every time any user (including a higher-privileged one) browses to the page listing it — a stepping stone to hijacking another operator's session on the KVM gateway.

Who can reach it

Requires an authenticated administrator account to upload/name the malicious file; the payload then fires against any user who later views that page.

What to do

Same fixed firmware/software build as the UMG-4000 command-injection issue (CVE-2019-9507) — apply both in the same maintenance window since they land in the same release. One flash per gateway.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.