Description
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
Published: 2019-09-25
Score: 7.5 High
EPSS: 11.5% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Ui Ep-r6 Ep-r6 Firmware Ep-r8 Ep-r8 Firmware Er-12 Er-12 Firmware Er-4 Er-4 Firmware Er-6p Er-6p Firmware Er-8 Er-8-xg Er-8-xg Firmware Er-8 Firmware Er-x Er-x-sfp Er-x-sfp Firmware Er-x Firmware Erlite-3 Erlite-3 Firmware Erpoe-5 Erpoe-5 Firmware Erpro-8 Erpro-8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:24:48.289Z

Reserved: 2019-09-25T00:00:00.000Z

Link: CVE-2019-16889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-25T20:15:11.120

Modified: 2024-11-21T04:31:16.817

Link: CVE-2019-16889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses