CVE-2019-9507
Summary
| CVE | CVE-2019-9507 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-30 22:15:00 UTC |
| Updated | 2021-11-03 19:32:00 UTC |
| Description | The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed as root, this could allow a remote attacker authenticated with an administrator account to execute arbitrary commands as root. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Vertiv | Avocent Umg-4000 | - | All | All | All |
| Hardware | Vertiv | Avocent Umg-4000 | - | All | All | All |
| Operating System | Vertiv | Avocent Umg-4000 Firmware | 4.2.1.19 | All | All | All |
| Operating System | Vertiv | Avocent Umg-4000 Firmware | 4.2.1.19 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Trellis™ Enterprise Software Downloads | MISC | www.vertiv.com | Vendor Advisory |
| Avocent Universal Management Gateway Appliance Software Downloads | MISC | www.vertiv.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.