7.8

CVE-2023-2379

Exploit

A vulnerability classified as critical has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Service. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227655.

Data is provided by the National Vulnerability Database (NVD)
UiEr-x Firmware Version < 2.0.9
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Update-
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix2
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix3
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix4
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix5
   UiEr-x Version-
UiEr-x Firmware Version2.0.9 Updatehotfix6
   UiEr-x Version-
UiEr-x-sfp Firmware Version < 2.0.9
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Update-
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix2
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix3
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix4
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix5
   UiEr-x-sfp Version-
UiEr-x-sfp Firmware Version2.0.9 Updatehotfix6
   UiEr-x-sfp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.277
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cna@vuldb.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cna@vuldb.com 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-404 Improper Resource Shutdown or Release

The product does not release or incorrectly releases a resource before it is made available for re-use.