Database/Firmware, BMC & network fabric

Lantronix PremierWave 2050 console server (Web Manager): Same class of bug as the Traceroute injection on this device
Impact
Same class of bug as the Traceroute injection on this device, reached through the Ping diagnostic instead — full command execution on the console server, with downstream reach into every serial line it terminates.
Who can reach it
Any authenticated Web Manager user submits a crafted host value to the Diagnostics: Ping function; the value flows unsanitized into a shell command.
What to do
Firmware upgrade past 8.9.0.0R4 and reboot. Same rollout cost as the Traceroute bug — treat both as one patch cycle per unit rather than two separate maintenance windows.
References
Related entries
- Lantronix PremierWave 2050 console server (Web Manager): An attacker who can log into the web management console getsCVE-2021-21872 · Lantronix PremierWave 2050 console server (Web Manager)Critical
- Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3): Unauthenticated remote code execution inCVE-2015-8812 · Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3)Critical
- Cisco NX-OS / FXOS (Cisco Fabric Services): Unauthenticated remote code execution as root through Cisco FabricCVE-2018-0314 · Cisco NX-OS / FXOS (Cisco Fabric Services)Critical
- Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directoryCVE-2018-12031 · Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameterCritical
- Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCVE-2018-1207 · Dell iDRAC7/8Critical
- Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems): An unprivilegedCVE-2018-12171 · Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.