ID

VAR-201904-0152


CVE

CVE-2019-5425


TITLE

Ubiquiti Networks EdgeSwitch X Command injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-003378

DESCRIPTION

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root. Ubiquiti Networks EdgeSwitch X Contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Ubiquiti Networks EdgeSwitch is a Gigabit network switch device from Ubiquiti Networks. A command injection vulnerability exists in Ubiquiti Networks EdgeSwitch X 1.1.0 and earlier. The vulnerability stems from the fact that the network system or product did not properly filter the special elements in the process of constructing executable commands from external input data. An attacker could use this vulnerability to execute an illegal command

Trust: 2.25

sources: NVD: CVE-2019-5425 // JVNDB: JVNDB-2019-003378 // CNVD: CNVD-2019-39181 // VULHUB: VHN-156860

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-39181

AFFECTED PRODUCTS

vendor:uimodel:edgeswitch xscope:lteversion:1.1.0

Trust: 1.0

vendor:ubiquitimodel:edgeswitch xscope:lteversion:1.1.0

Trust: 0.8

vendor:ubiquitimodel:networks edgeswitchscope:lteversion:<=1.1.0

Trust: 0.6

sources: CNVD: CNVD-2019-39181 // JVNDB: JVNDB-2019-003378 // NVD: CVE-2019-5425

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-5425
value: HIGH

Trust: 1.0

NVD: CVE-2019-5425
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-39181
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201904-534
value: HIGH

Trust: 0.6

VULHUB: VHN-156860
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-5425
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-39181
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-156860
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-5425
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-39181 // VULHUB: VHN-156860 // JVNDB: JVNDB-2019-003378 // CNNVD: CNNVD-201904-534 // NVD: CVE-2019-5425

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.1

problemtype:CWE-77

Trust: 0.9

sources: VULHUB: VHN-156860 // JVNDB: JVNDB-2019-003378 // NVD: CVE-2019-5425

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-534

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-201904-534

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-003378

PATCH

title:EdgeMAX EdgeSwitch X software release v1.1.1url:https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeSwitch-X-software-release-v1-1-1/ba-p/2731137

Trust: 0.8

title:Patch for Ubiquiti Networks EdgeSwitch X Command Injection Vulnerability (CNVD-2019-39181)url:https://www.cnvd.org.cn/patchInfo/show/188643

Trust: 0.6

title:Ubiquiti Networks EdgeSwitch Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91349

Trust: 0.6

sources: CNVD: CNVD-2019-39181 // JVNDB: JVNDB-2019-003378 // CNNVD: CNNVD-201904-534

EXTERNAL IDS

db:NVDid:CVE-2019-5425

Trust: 3.1

db:HACKERONEid:511025

Trust: 1.7

db:JVNDBid:JVNDB-2019-003378

Trust: 0.8

db:CNNVDid:CNNVD-201904-534

Trust: 0.7

db:CNVDid:CNVD-2019-39181

Trust: 0.6

db:VULHUBid:VHN-156860

Trust: 0.1

sources: CNVD: CNVD-2019-39181 // VULHUB: VHN-156860 // JVNDB: JVNDB-2019-003378 // CNNVD: CNNVD-201904-534 // NVD: CVE-2019-5425

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-5425

Trust: 2.0

url:https://community.ubnt.com/t5/edgemax-updates-blog/edgemax-edgeswitch-x-software-release-v1-1-1/ba-p/2731137

Trust: 1.7

url:https://hackerone.com/reports/511025

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-5425

Trust: 0.8

sources: CNVD: CNVD-2019-39181 // VULHUB: VHN-156860 // JVNDB: JVNDB-2019-003378 // CNNVD: CNNVD-201904-534 // NVD: CVE-2019-5425

SOURCES

db:CNVDid:CNVD-2019-39181
db:VULHUBid:VHN-156860
db:JVNDBid:JVNDB-2019-003378
db:CNNVDid:CNNVD-201904-534
db:NVDid:CVE-2019-5425

LAST UPDATE DATE

2024-11-23T22:21:43.966000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-39181date:2019-11-05T00:00:00
db:VULHUBid:VHN-156860date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-003378date:2019-05-16T00:00:00
db:CNNVDid:CNNVD-201904-534date:2021-08-16T00:00:00
db:NVDid:CVE-2019-5425date:2024-11-21T04:44:54.723

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-39181date:2019-11-05T00:00:00
db:VULHUBid:VHN-156860date:2019-04-10T00:00:00
db:JVNDBid:JVNDB-2019-003378date:2019-05-16T00:00:00
db:CNNVDid:CNNVD-201904-534date:2019-04-10T00:00:00
db:NVDid:CVE-2019-5425date:2019-04-10T18:29:00.557