Database/Firmware, BMC & network fabric

Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial port
CVSS 5.4CVE-2019-14456Firmware, BMC & network fabriccurated
Impact
Stored XSS injected from a device *connected to* a serial port — a compromised switch can attack the operator's console-server UI, inverting the expected trust direction
Who can reach it
Local device to OOB management UI
What to do
Console-server firmware upgrade to 4.5.0+; notable as an example of the OOB network being attackable from the devices it manages
References
Related entries
- AMD Secure Processor bootloader - SPIROM upgrade path: An attacker who can drive the SPIROM upgrade path can passCVE-2025-48515 · AMD Secure Processor bootloader - SPIROM upgrade pathMedium
- Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OSCVE-2025-7623 · Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-FMedium
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
- HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverCVE-2020-7202 · HPE iLO 4 / iLO 5 (unauthenticated information disclosure)Medium
- APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowCVE-2021-22815 · APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soCVE-2021-45925 · AMI MegaRAC SPx 12 / SPx 13 (BMC login)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.