Arbitrary Command Execution in Ubiquiti Networks EdgeSwitch X
CVE-2019-5424

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 April 2019

What is CVE-2019-5424?

The vulnerability in Ubiquiti Networks EdgeSwitch X allows a privileged user to execute arbitrary shell commands through the SSH CLI interface. This capability enables execution of commands with root privileges, potentially compromising the system's integrity and security.

Affected Version(s)

EdgeMAX EdgeSwitch X prior to v1.1.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.