Vulnerability Description
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Er-X Firmware | < 2.0.3 |
| Ui | Er-X | - |
| Ui | Er-X-Sfp Firmware | < 2.0.3 |
| Ui | Er-X-Sfp | - |
| Ui | Ep-R6 Firmware | < 2.0.3 |
| Ui | Ep-R6 | - |
| Ui | Erlite-3 Firmware | < 2.0.3 |
| Ui | Erlite-3 | - |
| Ui | Erpoe-5 Firmware | < 2.0.3 |
| Ui | Erpoe-5 | - |
| Ui | Er-8 Firmware | < 2.0.3 |
| Ui | Er-8 | - |
| Ui | Erpro-8 Firmware | < 2.0.3 |
| Ui | Erpro-8 | - |
| Ui | Ep-R8 Firmware | < 2.0.3 |
| Ui | Ep-R8 | - |
| Ui | Er-4 Firmware | < 2.0.3 |
| Ui | Er-4 | - |
| Ui | Er-6P Firmware | < 2.0.3 |
| Ui | Er-6P | - |
Related Weaknesses (CWE)
References
- https://community.ui.com/releases/New-EdgeRouter-firmware-2-0-3-has-been-releasePatchVendor Advisory
- https://hackerone.com/reports/406614ExploitIssue TrackingThird Party Advisory
- https://mjlanders.com/2019/07/28/resource-consumption-dos-on-edgemax-v1-10-6/ExploitThird Party Advisory
- https://community.ui.com/releases/New-EdgeRouter-firmware-2-0-3-has-been-releasePatchVendor Advisory
- https://hackerone.com/reports/406614ExploitIssue TrackingThird Party Advisory
- https://mjlanders.com/2019/07/28/resource-consumption-dos-on-edgemax-v1-10-6/ExploitThird Party Advisory
FAQ
What is CVE-2019-16889?
CVE-2019-16889 is a vulnerability with a CVSS score of 7.5 (HIGH). Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid...
How severe is CVE-2019-16889?
CVE-2019-16889 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16889?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Er-X Firmware, Ui Er-X, Ui Er-X-Sfp Firmware, Ui Er-X-Sfp, Ui Ep-R6 Firmware.