CVE-2019-5426
Summary
| CVE | CVE-2019-5426 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-10 18:29:00 UTC |
| Updated | 2020-10-16 19:28:00 UTC |
| Description | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ui | Edgeswitch X | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EdgeMAX EdgeSwitch X software release v1.1.1 - Ubiquiti Networks Community | CONFIRM | community.ubnt.com | Patch, Vendor Advisory |
| HackerOne | MISC | hackerone.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.