VYPR
Medium severity6.1NVD Advisory· Published May 27, 2024· Updated Apr 15, 2026

CVE-2024-34923

CVE-2024-34923

Description

In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before 01.07.00.00, there is reflected cross-site scripting (XSS).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in Avocent DSR2030 (03.04.00.07) and SVIP1020 (01.06.00.03) firmware allows arbitrary HTML/JS execution via crafted links.

Vulnerability

Overview

A reflected cross-site scripting (XSS) vulnerability exists in Avocent DSR2030 Appliance firmware versions prior to 03.07.01.23 and SVIP1020 Appliance firmware versions prior to 01.07.00.00 [1][2]. Reflected XSS occurs when an application does not properly validate or encode user-supplied data included in HTTP responses, enabling an attacker to inject malicious scripts into a victim's browser [2].

Attack

Vector and Prerequisites

Attackers can craft a malicious URL containing XSS payloads that, when clicked by an authenticated or unauthenticated user (depending on application context), will execute arbitrary HTML or JavaScript within the victim's session. No special network access beyond standard web traffic is required; the attack relies on social engineering to trick users into visiting the crafted link [2].

Impact

Successful exploitation allows an attacker to perform actions such as altering the displayed page content, redirecting the victim to attacker-controlled sites, stealing session credentials, or in some cases exploiting browser vulnerabilities to achieve code execution [2]. The CVSS v3 base score is 6.1 (Medium).

Mitigation

Avocent has released firmware updates to address the issue: version 03.07.01.23 for DSR2030 and version 01.07.00.00 for SVIP1020 [1][2]. Users should upgrade immediately to the fixed versions.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.