CVE-2019-16889: High severity ui edgerouter x firmware vulnerability
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because .cache files in /var/run/beaker/containerfile/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-16889?
CVE-2019-16889 is a vulnerability that allows remote attackers to cause a denial of service (disk consumption) on Ubiquiti EdgeMAX devices before version 2.0.3.
How do I determine if my Ubiquiti EdgeMAX device is affected?
You can check if your Ubiquiti EdgeMAX device is affected by verifying the firmware version. If it is before version 2.0.3, it is vulnerable.
What is the severity of CVE-2019-16889?
CVE-2019-16889 has a severity score of 7.5 (High).
How can I fix CVE-2019-16889?
To fix CVE-2019-16889, you need to update the firmware of your Ubiquiti EdgeMAX device to version 2.0.3 or later.
Where can I find more information about CVE-2019-16889?
You can find more information about CVE-2019-16889 at the following references: [link1], [link2], [link3].