Database/Firmware, BMC & network fabric

Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attacker
Impact
A reflected XSS in the appliance's web interface lets an attacker who can get an operator to click a crafted link run JavaScript in that operator's browser session — enough to steal their session cookie and act as them on the KVM appliance.
Who can reach it
Requires social engineering: the victim (an operator with legitimate access to the KVM appliance) has to click a link the attacker controls while authenticated to the device.
What to do
Software upgrade — DSR2030 to firmware 03.07.01.23 or later, SVIP1020 to 01.07.00.00 or later. Standard firmware flash per unit; no serial/KVM downtime beyond the reboot itself.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.