CVE-2019-16889

Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:er-x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-x:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ui:er-x-sfp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-x-sfp:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ui:ep-r6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:ep-r6:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ui:erlite-3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:erlite-3:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ui:erpoe-5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:erpoe-5:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ui:er-8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-8:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ui:erpro-8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:erpro-8:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ui:ep-r8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:ep-r8:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ui:er-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-4:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ui:er-6p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-6p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ui:er-12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-12:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ui:er-8-xg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:er-8-xg:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-09-25 20:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-16889

Mitre link : CVE-2019-16889

CVE.ORG link : CVE-2019-16889


JSON object : View

Products Affected

ui

  • er-x
  • erpro-8
  • erpoe-5
  • ep-r6_firmware
  • er-4_firmware
  • er-8-xg
  • er-12_firmware
  • erpro-8_firmware
  • er-8
  • er-x-sfp_firmware
  • erlite-3
  • er-8-xg_firmware
  • er-6p
  • er-8_firmware
  • ep-r6
  • er-12
  • erlite-3_firmware
  • ep-r8
  • er-x_firmware
  • erpoe-5_firmware
  • er-x-sfp
  • ep-r8_firmware
  • er-4
  • er-6p_firmware
CWE
CWE-770

Allocation of Resources Without Limits or Throttling