Database/Control plane, storage & DevOps

Vertiv Avocent UMG-4000 universal management gateway: An authenticated admin can plant a maliciously named file
Impact
An authenticated admin can plant a maliciously named file in the web application that executes JavaScript every time any user (including a higher-privileged one) browses to the page listing it — a stepping stone to hijacking another operator's session on the KVM gateway.
Who can reach it
Requires an authenticated administrator account to upload/name the malicious file; the payload then fires against any user who later views that page.
What to do
Same fixed firmware/software build as the UMG-4000 command-injection issue (CVE-2019-9507) — apply both in the same maintenance window since they land in the same release. One flash per gateway.
References
Related entries
- Vertiv Avocent UMG-4000 universal management gateway: Every command the UMG-4000's web interface runs executes as rootCVE-2019-9507 · Vertiv Avocent UMG-4000 universal management gatewayHigh
- Slurm (openSUSE slurm-testsuite packaging): The openSUSE slurm testsuite package ships files with permissive defaultCVE-2022-31251 · Slurm (openSUSE slurm-testsuite packaging)Medium
- Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups meansCVE-2024-20280 · Cisco UCS Central Software (weak backup encryption)Medium
- Dell OpenManage Enterprise (credential disclosure): A low-privileged local user obtains stored credentials from OMECVE-2024-28961 · Dell OpenManage Enterprise (credential disclosure)Medium
- Grafana: org admin can delete other organizations' snapshots and recover delete keys from share keysCVE-2026-19197 · Grafana (dashboard snapshot API)Medium
- CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching): Stack-based buffer overflow in BIRD's AS_PATH maskCVE-2026-49943 · CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.