GPU VulnDB

Database/Firmware, BMC & network fabric

Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attacker

CVE-2024-34923Firmware, BMC & network fabriccurated

Impact

A reflected XSS in the appliance's web interface lets an attacker who can get an operator to click a crafted link run JavaScript in that operator's browser session — enough to steal their session cookie and act as them on the KVM appliance.

Who can reach it

Requires social engineering: the victim (an operator with legitimate access to the KVM appliance) has to click a link the attacker controls while authenticated to the device.

What to do

Software upgrade — DSR2030 to firmware 03.07.01.23 or later, SVIP1020 to 01.07.00.00 or later. Standard firmware flash per unit; no serial/KVM downtime beyond the reboot itself.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.