← Back

Edgeswitch X

edgeswitch_x

Vendor: Ui • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ui
1Edgeswitch X
Nov 21, 2024
Apr 10, 2019
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploi...Show more
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings.Show less
1Ui
1Edgeswitch X
Nov 21, 2024
Apr 10, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root.
1Ui
1Edgeswitch X
Nov 21, 2024
Apr 10, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user.