First published: Wed Jul 10 2019(Updated: )
Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubiquiti EdgeSwitch Firmware | <1.8.2 | |
ui ep-s16 | ||
UI ES-12F | ||
ui es-16-150w | ||
UI ES-16-XG | ||
ui es-24-250w | ||
ui es-24-500w | ||
ui es-24-lite | ||
UI ES-48-500W | ||
UI ES-48-750W | ||
ui es-48-lite | ||
ui es-8-150w |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-5446.
The severity of CVE-2019-5446 is critical with a severity value of 7.2.
EdgeMAX EdgeSwitch versions prior to 1.8.2 are affected by CVE-2019-5446.
An Admin user can exploit CVE-2019-5446 by executing commands as root.
Yes, a fix for CVE-2019-5446 is available in EdgeMAX EdgeSwitch Firmware v1.8.2.