Denial of Service Vulnerability in airMAX and EdgeMAX Products by Ubiquiti Networks
CVE-2017-0938

7.5HIGH

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
6 February 2019

What is CVE-2017-0938?

A vulnerability exists in Ubiquiti Networks' airMAX and EdgeMAX products that allows attackers to exploit the Discovery Protocol to launch Denial of Service attacks. This issue is present in versions prior to airMAX 8.3.2, airMAX 6.0.7, and EdgeMAX 1.9.7. Attackers can execute amplification attacks, potentially disrupting service and accessibility for legitimate users.

Affected Version(s)

airMAX, EdgeMAX airMAX < 8.3.2, airMAX < 6.0.7, EdgeRouter < v1.9.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.