GPU VulnDB

Database/Firmware, BMC & network fabric

Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial port

CVE-2019-14456Firmware, BMC & network fabriccurated

Impact

Stored XSS injected from a device *connected to* a serial port — a compromised switch can attack the operator's console-server UI, inverting the expected trust direction

Who can reach it

Local device to OOB management UI

What to do

Console-server firmware upgrade to 4.5.0+; notable as an example of the OOB network being attackable from the devices it manages

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.