CVE-2019-5446: Command Injection
Published Jul 10, 2019
·Updated
Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
Affected Software
12 affected components
UI Edgeswitch Firmware<1.8.2
UI Ep-s16.
UI Es-12f
UI Es-16-150w
UI Es-16-xg
UI Es-24-250w
UI Es-24-500w
UI Es-24-lite
UI Es-48-500w
UI Es-48-750w
UI Es-48-lite
UI Es-8-150w
Event History
Jul 10, 2019
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this command injection in EdgeMAX EdgeSwitch?
The vulnerability ID is CVE-2019-5446.
2
What is the severity of CVE-2019-5446?
The severity of CVE-2019-5446 is critical with a severity value of 7.2.
3
Which versions of EdgeMAX EdgeSwitch are affected by CVE-2019-5446?
EdgeMAX EdgeSwitch versions prior to 1.8.2 are affected by CVE-2019-5446.
4
How can an Admin user exploit CVE-2019-5446?
An Admin user can exploit CVE-2019-5446 by executing commands as root.
5
Is there a fix available for CVE-2019-5446?
Yes, a fix for CVE-2019-5446 is available in EdgeMAX EdgeSwitch Firmware v1.8.2.