Ubiquiti Networks Edgemax vulnerabilities

5 known vulnerabilities affecting ubiquiti_networks/edgemax.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2019-5446HIGHCVSS 7.2v1.8.12019-07-10
CVE-2019-5446 [HIGH] CWE-77 CVE-2019-5446: Command Injection in EdgeMAX EdgeSwitch prior to 1 Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
cvelistv5
CVE-2019-5445MEDIUMCVSS 4.9v1.8.12019-07-10
CVE-2019-5445 [MEDIUM] CWE-400 CVE-2019-5445: DoS in EdgeMAX EdgeSwitch prior to 1 DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.
cvelistv5
CVE-2019-5425HIGHCVSS 8.8vEdgeSwitch X prior to v1.1.12019-04-10
CVE-2019-5425 [HIGH] CWE-78 CVE-2019-5425: In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shel In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root.
cvelistv5nvd
CVE-2019-5424HIGHCVSS 8.8vEdgeSwitch X prior to v1.1.12019-04-10
CVE-2019-5424 [HIGH] CWE-77 CVE-2019-5424: In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell co In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user.
cvelistv5nvd
CVE-2019-5426MEDIUMCVSS 4.8vEdgeSwitch X prior to v1.1.12019-04-10
CVE-2019-5426 [MEDIUM] CWE-287 CVE-2019-5426: In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings.
cvelistv5nvd