Database/Firmware, BMC & network fabric

Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attacker
Impact
A reflected XSS in the appliance's web interface lets an attacker who can get an operator to click a crafted link run JavaScript in that operator's browser session — enough to steal their session cookie and act as them on the KVM appliance.
Who can reach it
Requires social engineering: the victim (an operator with legitimate access to the KVM appliance) has to click a link the attacker controls while authenticated to the device.
What to do
Software upgrade — DSR2030 to firmware 03.07.01.23 or later, SVIP1020 to 01.07.00.00 or later. Standard firmware flash per unit; no serial/KVM downtime beyond the reboot itself.
References
Related entries
- Intel Xeon 6 E-core with TDX or SGX: Improper restriction of software interfaces to hardware features on Xeon 6 E-coreCVE-2024-48869 · Intel Xeon 6 E-core with TDX or SGXMedium
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineCVE-2022-36382 · Intel Ethernet E810 Series and Ethernet 700 Series firmwareMedium
- Intel processors with SGX (shared resource isolation): Improper isolation of shared microarchitectural resources lets aCVE-2022-38090 · Intel processors with SGX (shared resource isolation)Medium
- Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit): The dynamic-counter netlink setter bounded itsCVE-2022-49199 · Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit)Medium
- AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILURECVE-2023-31355 · AMD SEV-SNP firmware, guest teardown / UMC key seed handlingMedium
- AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handlerCVE-2023-34342 · AMI MegaRAC SPx (IPMI handler)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.