{}

Our Brands

Search FAQs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability (NMC3 RPDU2G)

Issue:
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists when an outlet user can create a “outlet link” which could allow the security token for a superuser to be forwarded to a machine controlled by the attacker, allowing the user to access the system with elevated privileges. Specifying all links as no referrer blocks the security token from being sent.

Product Lines:
ProductVersion
AP7xxxx and AP8xxx with NMC2V6.9.6 or earlier
AP7xxx and AP8xxx with NMC3v1.1.0.3 or earlier
APDU9xxx with NMC3v1.0.0.28 or earlier


Solution:
A firmware update has been made available to address CWE-79, and has been attached to this article. Please use the below chart to select the proper firmware version.
AP7xxxx and AP8xxx with NMC2v7.0.6 of the Rack PDU firmware includes a fix for this vulnerability and is available for download here
AP7xxx and AP8xxx with NMC3v1.2.0.2 of the Rack PDU firmware includes a fix for this vulnerability and is available for download here
APDU9xxx with NMC3v1.2.0.2 of the Rack PDU firmware includes a fix for this vulnerability and is available for download here

APC Hong Kong

Attachment(s)

apc_hw21_rpdu2g_1-2-0-2.zipapc_hw21_rpdu2g_1-2-0-2.zip [3.32 MB]
release notes v1.2.0.2.pdfrelease notes v1.2.0.2.pdf [93.27 KB]
apc_hw05_aos704_rpdu2g706_bootmon109.exeapc_hw05_aos704_rpdu2g706_bootmon109.exe [3.17 MB]
release notes v7.0.6.pdfrelease notes v7.0.6.pdf [112.56 KB]
Explore more
Range:
NetShelter Switched Rack PDUsRack PDU Accessories
Explore more
Range:
NetShelter Switched Rack PDUsRack PDU Accessories
Users group

Discuss this topic with experts

Visit our Community for first-hand insights from experts and peers on this topic and more.