Vulnerability Description
A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes command injection. The attack may be initiated remotely. The exploit has been published and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor position is that post-authentication issues are not accepted as vulnerabilities.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Er-X Firmware | < 2.0.9 |
| Ui | Er-X | - |
| Ui | Er-X-Sfp Firmware | < 2.0.9 |
| Ui | Er-X-Sfp | - |
Related Weaknesses (CWE)
References
- https://github.com/leetsun/IoT/tree/main/EdgeRouterX/CI/4ExploitThird Party Advisory
- https://vuldb.com/cve/CVE-2023-2378
- https://vuldb.com/submit/114072
- https://vuldb.com/vuln/227654
- https://vuldb.com/vuln/227654/cti
- https://github.com/leetsun/IoT/tree/main/EdgeRouterX/CI/4ExploitThird Party Advisory
- https://vuldb.com/?ctiid.227654Third Party Advisory
- https://vuldb.com/?id.227654Third Party Advisory
FAQ
What is CVE-2023-2378?
CVE-2023-2378 is a vulnerability with a CVSS score of 7.2 (HIGH). A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes...
How severe is CVE-2023-2378?
CVE-2023-2378 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2378?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Er-X Firmware, Ui Er-X, Ui Er-X-Sfp Firmware, Ui Er-X-Sfp.