An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NUi Edgeswitch Firmware
APPUi< 1.9.0Ui Ep 16 Xg
HWUiall versionsUi Ep S16
HWUiall versionsUi Es 12f
HWUiall versionsUi Es 16 150w
HWUiall versionsUi Es 24 250w
HWUiall versionsUi Es 24 500w
HWUiall versionsUi Es 24 Lite
HWUiall versionsUi Es 48 500w
HWUiall versionsUi Es 48 750w
HWUiall versionsUi Es 48 Lite
HWUiall versionsUi Es 8 150w
HWUiall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2020-8234CRITICAL9.8PL ✓same product
Możliwość odgadnięcia cookie SIDSSL w EdgeSwitch umożliwia RCE jako root
CVE-2020-8233HIGH8.8same product
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-onl...
CVE-2019-5446HIGH7.2same product
Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
CVE-2018-12590HIGH7.2same product
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulner...
CVE-2019-5445MEDIUM4.9same product
DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted c...