CVE-2019-16889
25.09.2019, 20:15
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.Enginsight
Vendor | Product | Version |
---|---|---|
ui | er-x_firmware | 𝑥 < 2.0.3 |
ui | er-x-sfp_firmware | 𝑥 < 2.0.3 |
ui | ep-r6_firmware | 𝑥 < 2.0.3 |
ui | erlite-3_firmware | 𝑥 < 2.0.3 |
ui | erpoe-5_firmware | 𝑥 < 2.0.3 |
ui | er-8_firmware | 𝑥 < 2.0.3 |
ui | erpro-8_firmware | 𝑥 < 2.0.3 |
ui | ep-r8_firmware | 𝑥 < 2.0.3 |
ui | er-4_firmware | 𝑥 < 2.0.3 |
ui | er-6p_firmware | 𝑥 < 2.0.3 |
ui | er-12_firmware | 𝑥 < 2.0.3 |
ui | er-8-xg_firmware | 𝑥 < 2.0.3 |
𝑥
= Vulnerable software versions
References