Database/Firmware, BMC & network fabric

Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forces
Impact
CSRF on the change-password function plus reflected XSS: an attacker forces a silent password change on the UPS admin account and takes over the device. Once they hold the UPS admin account they control shutdown behaviour and output for whatever the unit feeds - a PHYSICAL outcome from a web bug.
Who can reach it
Requires a logged-in UPS administrator to load an attacker-controlled page.
What to do
Firmware update on the UPS network card where available. On units this age, availability of a fix is not guaranteed - if none exists, the mitigation is a dedicated management VLAN, no browser access to UPS interfaces from general-purpose workstations, and disabling the web interface if the unit can be managed another way.
References
Related entries
- Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710): Buffer overflow in the adapter firmware of Intel'sCVE-2019-0140 · Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710)High
- Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalationCVE-2019-0169 · Intel CSME / TXEHigh
- Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own descriptionCVE-2019-19642 · Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06High
- NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web applicationCVE-2020-11485 · NVIDIA DGX BMC (AMI firmware)High
- Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40): Arbitrary code execution on the rack PDUCVE-2020-11953 · Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40)High
- OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass): The file holding IPMI account passwordsCVE-2020-14156 · OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.