Database/Control plane, storage & DevOps

Vertiv Avocent UMG-4000 universal management gateway: Every command the UMG-4000's web interface runs executes as root
Impact
Every command the UMG-4000's web interface runs executes as root on the underlying OS. An admin-authenticated attacker who can inject shell syntax into a web form gets root on the gateway — which sits between the operator and every server it's providing KVM/serial access to.
Who can reach it
Requires an authenticated administrator session on the web interface; the app fails to neutralize shell metacharacters before executing commands.
What to do
Software/firmware upgrade from Vertiv; download the fixed build from Vertiv's Avocent UMG support page and flash each gateway. Since the UMG-4000 is the aggregation point for KVM access to many downstream nodes, schedule the update in a maintenance window and expect KVM sessions through that gateway to drop during the flash.
References
Related entries
- Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named fileCVE-2019-9508 · Vertiv Avocent UMG-4000 universal management gatewayMedium
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic eval: Unauthenticated eval injection: user-controlledCVE-2021-23277 · Eaton Intelligent Power Manager (IPM) prior to 1.69 - dynamic evalHigh
- Intel C++ Compiler Classic / oneAPI toolkits (Unicode source handling): Improper handling of Unicode bidirectionalCVE-2022-25987 · Intel C++ Compiler Classic / oneAPI toolkits (Unicode source handling)High
- Intel oneAPI DPC++/C++ compiler (homoglyph rendering): Homoglyph characters are not visually distinguishedCVE-2022-26843 · Intel oneAPI DPC++/C++ compiler (homoglyph rendering)High
- Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authenticationCVE-2025-0052 · Pure Storage FlashBlade authentication input validationHigh
- Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack bufferCVE-2025-26336 · Dell Chassis Management Controller (PowerEdge FX2 / VRTX)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.