Database/Firmware, BMC & network fabric

APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflected
Impact
Stored/reflected cross-site scripting in the NMC2 policy-file pages. On its own it is a browser bug; in context it is a route to hijack a facility engineer's authenticated session on the card that controls UPS behaviour. An attacker with an NMC session can change shutdown policies, thresholds and outlet-group behaviour - which is a path to a power event, not just a defacement.
Who can reach it
Requires tricking an already-privileged NMC user into clicking a crafted URL. Realistic in a colo where facility staff routinely click links in tickets.
What to do
Firmware update to NMC2 AOS v6.9.6 or later (SEVD-2021-313-03 covers the whole CVE-2021-22810 through -22815 batch, so treat it as one campaign). Non-disruptive flash. Enforce that NMC admin sessions are only opened from a dedicated management workstation.
References
Related entries
- Arista EOS (TerminAttr / OpenConfig telemetry transport): The streaming-telemetry agent can leak MACsec keys over theCVE-2021-28509 · Arista EOS (TerminAttr / OpenConfig telemetry transport)Medium
- IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interfaceCVE-2021-38961 · IBM OpenBMC OP910 web UI (phosphor-webui lineage)Medium
- Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): A protection mechanism in 3rd and 4th generationCVE-2023-22655 · Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure)Medium
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingCVE-2023-40546 · shim (mok.c mirror_one_esl)Medium
- Linux kernel (drivers/pci/switch): If a userspace process is holding the Switchtec management character device openCVE-2023-52617 · Linux kernel (drivers/pci/switch)Medium
- Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attackerCVE-2024-34923 · Avocent DSR2030 / SVIP1020 KVM-over-IP applianceMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.