HIGH✓ PATCH🇬🇧 English

CVE-2017-0938

CVSS 7.5v3.1pub. 2019-02-12upd. 2024-11-21

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Ui Airmax Ac

    HW
    Ui
    wszystkie wersje
  • Ui Airos

    OS
    Ui
    < 6.0.76.0.7 – 8.3.2 (bez)
  • Ui Edgemax

    HW
    Ui
    wszystkie wersje
  • Ui Edgemax Firmware

    OS
    Ui
    < 1.9.7
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
DoS
CWE
Referencje

Powiązane podatności

CVE-2010-5330CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Command injection w Ubiquiti AirOS via stainfo.cgi (ifname)

CVE-2020-8234CRITICAL9.8PL ✓ten sam produkt

Możliwość odgadnięcia cookie SIDSSL w EdgeSwitch umożliwia RCE jako root

CVE-2020-8171CRITICAL9.8PL ✓ten sam produkt

Command Injection / RCE w firmware Ubiquiti AirMax AirOS

CVE-2015-9266CRITICAL9.8PL ✓ten sam produkt

Ubiquiti airMAX/airFiber/EdgeSwitch XP — path traversal umożliwia zapis plików jako root

CVE-2026-21639HIGH8.8ten sam produkt

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless...