Database/Firmware, BMC & network fabric

APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflected
Impact
Stored/reflected cross-site scripting in the NMC2 policy-file pages. On its own it is a browser bug; in context it is a route to hijack a facility engineer's authenticated session on the card that controls UPS behaviour. An attacker with an NMC session can change shutdown policies, thresholds and outlet-group behaviour - which is a path to a power event, not just a defacement.
Who can reach it
Requires tricking an already-privileged NMC user into clicking a crafted URL. Realistic in a colo where facility staff routinely click links in tickets.
What to do
Firmware update to NMC2 AOS v6.9.6 or later (SEVD-2021-313-03 covers the whole CVE-2021-22810 through -22815 batch, so treat it as one campaign). Non-disruptive flash. Enforce that NMC admin sessions are only opened from a dedicated management workstation.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.