7.8
CVE-2023-2379
- EPSS 0.09%
- Veröffentlicht 28.04.2023 17:15:43
- Zuletzt bearbeitet 21.11.2024 07:58:29
- Quelle cna@vuldb.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability classified as critical has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Service. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227655.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ui ≫ Er-x Firmware Version < 2.0.9
Ui ≫ Er-x Firmware Version2.0.9 Update-
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix3
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-x Firmware Version2.0.9 Updatehotfix6
Ui ≫ Er-x-sfp Firmware Version < 2.0.9
Ui ≫ Er-x-sfp Firmware Version2.0.9 Update-
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix2
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix3
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix4
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix5
Ui ≫ Er-x-sfp Firmware Version2.0.9 Updatehotfix6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.277 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
cna@vuldb.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
cna@vuldb.com | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-404 Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.