7.5
CVE-2023-2379
- EPSS 1.29%
- Veröffentlicht 28.04.2023 17:15:43
- Zuletzt bearbeitet 21.11.2024 07:58:29
- Erkennungen
Ubiquiti EdgeRouter X Web Service denial of service
A vulnerability classified as critical has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Service. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227655.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ui ≫ Er-x Firmware Version < 2.0.9
Ui ≫ Er-x Firmware Version 2.0.9 Update -
Ui ≫ Er-x Firmware Version 2.0.9 Update hotfix2
Ui ≫ Er-x Firmware Version 2.0.9 Update hotfix3
Ui ≫ Er-x Firmware Version 2.0.9 Update hotfix4
Ui ≫ Er-x Firmware Version 2.0.9 Update hotfix5
Ui ≫ Er-x Firmware Version 2.0.9 Update hotfix6
Ui ≫ Er-x-sfp Firmware Version < 2.0.9
Ui ≫ Er-x-sfp Firmware Version 2.0.9 Update -
Ui ≫ Er-x-sfp Firmware Version 2.0.9 Update hotfix2
Ui ≫ Er-x-sfp Firmware Version 2.0.9 Update hotfix3
Ui ≫ Er-x-sfp Firmware Version 2.0.9 Update hotfix4
Ui ≫ Er-x-sfp Firmware Version 2.0.9 Update hotfix5
Ui ≫ Er-x-sfp Firmware Version 2.0.9 Update hotfix6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.29% | 0.664 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cna@vuldb.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cna@vuldb.com | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-404 Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
https://github.com/leetsun/IoT/tree/main/EdgeRouterX/DoS
https://vuldb.com/?ctiid.227655
https://vuldb.com/?id.227655