Database/Firmware, BMC & network fabric

Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial port
CVE-2019-14456Firmware, BMC & network fabriccurated
Impact
Stored XSS injected from a device *connected to* a serial port — a compromised switch can attack the operator's console-server UI, inverting the expected trust direction
Who can reach it
Local device to OOB management UI
What to do
Console-server firmware upgrade to 4.5.0+; notable as an example of the OOB network being attackable from the devices it manages
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.