CVE-2019-16889

Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:er-x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-x:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ui:er-x-sfp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-x-sfp:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ui:ep-r6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:ep-r6:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ui:erlite-3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:erlite-3:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ui:erpoe-5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:erpoe-5:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ui:er-8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-8:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ui:erpro-8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:erpro-8:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ui:ep-r8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:ep-r8:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ui:er-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-4:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ui:er-6p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-6p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ui:er-12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-12:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ui:er-8-xg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-8-xg:-:*:*:*:*:*:*:*

Information

Published : 2019-09-25 13:15

Updated : 2020-08-24 10:37


NVD link : CVE-2019-16889

Mitre link : CVE-2019-16889


JSON object : View

CWE
CWE-770

Allocation of Resources Without Limits or Throttling

Advertisement

dedicated server usa

Products Affected

ui

  • ep-r8
  • er-6p
  • er-8-xg_firmware
  • erpro-8
  • er-12_firmware
  • erlite-3_firmware
  • erpoe-5_firmware
  • ep-r6_firmware
  • er-4_firmware
  • er-4
  • er-x-sfp
  • erpoe-5
  • er-12
  • er-x-sfp_firmware
  • erpro-8_firmware
  • ep-r8_firmware
  • er-x
  • er-6p_firmware
  • erlite-3
  • er-8-xg
  • er-x_firmware
  • er-8
  • er-8_firmware
  • ep-r6