ID

VAR-201803-1000


CVE

CVE-2017-0932


TITLE

Ubiquiti Networks EdgeOS Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2017-012986

DESCRIPTION

Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the input of the Feature functionality. An attacker with access to an operator (read-only) account and ssh connection to the devices could escalate privileges to admin (root) access in the system. Ubiquiti Networks EdgeOS Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Ubiquiti Networks EdgeOS is an operating system of Ubiquiti Networks that runs on Ubiquiti products. A security vulnerability exists in Ubiquiti Networks EdgeOS 1.9.1.1 and earlier versions. The vulnerability is caused by the program not validating the input to the security function. An attacker could exploit this vulnerability to elevate privileges to administrator (root) privileges

Trust: 1.71

sources: NVD: CVE-2017-0932 // JVNDB: JVNDB-2017-012986 // VULHUB: VHN-99751

AFFECTED PRODUCTS

vendor:ubntmodel:edgeosscope:lteversion:1.9.1.1

Trust: 1.0

vendor:ubiquitimodel:edgeosscope:lteversion:1.9.1.1

Trust: 0.8

vendor:ubntmodel:edgeosscope:eqversion:1.9.1.1

Trust: 0.6

sources: JVNDB: JVNDB-2017-012986 // CNNVD: CNNVD-201803-806 // NVD: CVE-2017-0932

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-0932
value: HIGH

Trust: 1.0

NVD: CVE-2017-0932
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201803-806
value: HIGH

Trust: 0.6

VULHUB: VHN-99751
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-0932
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-99751
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-0932
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-99751 // JVNDB: JVNDB-2017-012986 // CNNVD: CNNVD-201803-806 // NVD: CVE-2017-0932

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-99751 // JVNDB: JVNDB-2017-012986 // NVD: CVE-2017-0932

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-806

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201803-806

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-012986

PATCH

title:EdgeMAX EdgeRouter software security release v1.9.7+hotfix.3url:https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-security-release-v1-9-7-hotfix-3/ba-p/2054117

Trust: 0.8

title:Ubiquiti Networks EdgeOS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79367

Trust: 0.6

sources: JVNDB: JVNDB-2017-012986 // CNNVD: CNNVD-201803-806

EXTERNAL IDS

db:NVDid:CVE-2017-0932

Trust: 2.5

db:HACKERONEid:239719

Trust: 1.7

db:JVNDBid:JVNDB-2017-012986

Trust: 0.8

db:CNNVDid:CNNVD-201803-806

Trust: 0.7

db:VULHUBid:VHN-99751

Trust: 0.1

sources: VULHUB: VHN-99751 // JVNDB: JVNDB-2017-012986 // CNNVD: CNNVD-201803-806 // NVD: CVE-2017-0932

REFERENCES

url:https://community.ubnt.com/t5/edgemax-updates-blog/edgemax-edgerouter-software-security-release-v1-9-7-hotfix-3/ba-p/2054117

Trust: 1.7

url:https://hackerone.com/reports/239719

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-0932

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-0932

Trust: 0.8

sources: VULHUB: VHN-99751 // JVNDB: JVNDB-2017-012986 // CNNVD: CNNVD-201803-806 // NVD: CVE-2017-0932

SOURCES

db:VULHUBid:VHN-99751
db:JVNDBid:JVNDB-2017-012986
db:CNNVDid:CNNVD-201803-806
db:NVDid:CVE-2017-0932

LAST UPDATE DATE

2024-11-23T22:59:05.503000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-99751date:2019-10-09T00:00:00
db:JVNDBid:JVNDB-2017-012986date:2018-05-15T00:00:00
db:CNNVDid:CNNVD-201803-806date:2019-10-17T00:00:00
db:NVDid:CVE-2017-0932date:2024-11-21T03:03:55.460

SOURCES RELEASE DATE

db:VULHUBid:VHN-99751date:2018-03-22T00:00:00
db:JVNDBid:JVNDB-2017-012986date:2018-05-15T00:00:00
db:CNNVDid:CNNVD-201803-806date:2018-03-23T00:00:00
db:NVDid:CVE-2017-0932date:2018-03-22T14:29:00.223