ID

VAR-201803-1002


CVE

CVE-2017-0934


TITLE

Ubiquiti Networks EdgeOS Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2017-012988

DESCRIPTION

Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an operator (read-only) account could escalate privileges to admin (root) access in the system. Ubiquiti Networks EdgeOS Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Ubiquiti Networks EdgeOS is an operating system of Ubiquiti Networks that runs on Ubiquiti products. A security vulnerability exists in Ubiquiti Networks EdgeOS 1.9.1 and earlier versions. The vulnerability stems from the program's lack of protection for the file system. An attacker could exploit this vulnerability to obtain sensitive information and elevate to administrator privileges

Trust: 1.71

sources: NVD: CVE-2017-0934 // JVNDB: JVNDB-2017-012988 // VULHUB: VHN-99753

AFFECTED PRODUCTS

vendor:ubntmodel:edgeosscope:lteversion:1.9.1

Trust: 1.0

vendor:ubiquitimodel:edgeosscope:lteversion:1.9.1

Trust: 0.8

vendor:ubntmodel:edgeosscope:eqversion:1.9.1

Trust: 0.6

sources: JVNDB: JVNDB-2017-012988 // CNNVD: CNNVD-201803-804 // NVD: CVE-2017-0934

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-0934
value: HIGH

Trust: 1.0

NVD: CVE-2017-0934
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201803-804
value: HIGH

Trust: 0.6

VULHUB: VHN-99753
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-0934
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-99753
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-0934
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-99753 // JVNDB: JVNDB-2017-012988 // CNNVD: CNNVD-201803-804 // NVD: CVE-2017-0934

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-99753 // JVNDB: JVNDB-2017-012988 // NVD: CVE-2017-0934

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-804

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201803-804

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-012988

PATCH

title:EdgeMAX EdgeRouter software release v1.9.1.1url:https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-release-v1-9-1-1/ba-p/1910524

Trust: 0.8

title:Ubiquiti Networks EdgeOS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79365

Trust: 0.6

sources: JVNDB: JVNDB-2017-012988 // CNNVD: CNNVD-201803-804

EXTERNAL IDS

db:NVDid:CVE-2017-0934

Trust: 2.5

db:HACKERONEid:241044

Trust: 1.7

db:JVNDBid:JVNDB-2017-012988

Trust: 0.8

db:CNNVDid:CNNVD-201803-804

Trust: 0.6

db:VULHUBid:VHN-99753

Trust: 0.1

sources: VULHUB: VHN-99753 // JVNDB: JVNDB-2017-012988 // CNNVD: CNNVD-201803-804 // NVD: CVE-2017-0934

REFERENCES

url:https://community.ubnt.com/t5/edgemax-updates-blog/edgemax-edgerouter-software-release-v1-9-1-1/ba-p/1910524

Trust: 1.7

url:https://hackerone.com/reports/241044

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-0934

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-0934

Trust: 0.8

sources: VULHUB: VHN-99753 // JVNDB: JVNDB-2017-012988 // CNNVD: CNNVD-201803-804 // NVD: CVE-2017-0934

SOURCES

db:VULHUBid:VHN-99753
db:JVNDBid:JVNDB-2017-012988
db:CNNVDid:CNNVD-201803-804
db:NVDid:CVE-2017-0934

LAST UPDATE DATE

2024-11-23T21:53:20.933000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-99753date:2019-10-09T00:00:00
db:JVNDBid:JVNDB-2017-012988date:2018-05-15T00:00:00
db:CNNVDid:CNNVD-201803-804date:2019-10-17T00:00:00
db:NVDid:CVE-2017-0934date:2024-11-21T03:03:55.690

SOURCES RELEASE DATE

db:VULHUBid:VHN-99753date:2018-03-22T00:00:00
db:JVNDBid:JVNDB-2017-012988date:2018-05-15T00:00:00
db:CNNVDid:CNNVD-201803-804date:2018-03-23T00:00:00
db:NVDid:CVE-2017-0934date:2018-03-22T14:29:00.347