In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2019-04-10T17:53:05

Updated: 2024-08-04T19:54:53.513Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-04-10T18:29:00.620

Modified: 2020-10-16T19:28:23.400

Link: CVE-2019-5426

cve-icon Redhat

No data.