PT-2020-11356 · Vertiv · Vertiv Avocent Umg-4000
Published
2020-03-30
·
Updated
2021-11-03
·
CVE-2019-9507
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vertiv Avocent UMG-4000 version 4.2.1.19
Description
The web interface of the Vertiv Avocent UMG-4000 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed as root, this could allow a remote attacker authenticated with an administrator account to execute arbitrary commands as root.
Recommendations
For Vertiv Avocent UMG-4000 version 4.2.1.19, consider disabling the web interface or restricting access to it until a patch is available to prevent command injection attacks. Additionally, restrict administrator account access to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vertiv Avocent Umg-4000