CVE-2017-0938: Input Validation
Published Feb 12, 2019
·Updated
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.
Affected Software
5 affected components
UI AirOS<6.0.7
UI airMAX AC
UI AirOS>=6.0.7<8.3.2
UI Edgemax Firmware<1.9.7
UI Edgemax
Event History
Feb 12, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-0938?
CVE-2017-0938 is a vulnerability that allows for a Denial of Service attack in airMAX < 8.3.2, airMAX < 6.0.7, and EdgeMAX < 1.9.7.
2
What is the severity of CVE-2017-0938?
CVE-2017-0938 has a severity rating of 7.5, which is considered high.
3
How does CVE-2017-0938 work?
CVE-2017-0938 allows attackers to use the Discovery Protocol in amplification attacks, leading to a Denial of Service.
4
Which software versions are affected by CVE-2017-0938?
airMAX versions < 8.3.2, airMAX < 6.0.7, and EdgeMAX versions < 1.9.7 are affected by CVE-2017-0938.
5
How can I fix CVE-2017-0938?
To fix CVE-2017-0938, it is recommended to update airMAX to version 8.3.2 or above, airMAX < 6.0.7, and EdgeMAX to version 1.9.7 or above.