9

CVE-2019-5446

Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ui ≫ Edgeswitch Firmware Version < 1.8.2
   Ui ≫ Ep-s16. Version -
   Ui ≫ Es-12f Version -
   Ui ≫ Es-16-150w Version -
   Ui ≫ Es-16-xg Version -
   Ui ≫ Es-24-250w Version -
   Ui ≫ Es-24-500w Version -
   Ui ≫ Es-24-lite Version -
   Ui ≫ Es-48-500w Version -
   Ui ≫ Es-48-750w Version -
   Ui ≫ Es-48-lite Version -
   Ui ≫ Es-8-150w Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.66% 0.837
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-8-2/824d58b1-6027-49cf-878d-2076c01948b7
Vendor Advisory
Release Notes