CVE-2017-0938

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:airos:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ui:airos:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ui:edgemax_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:edgemax:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:03

Type Values Removed Values Added
References () https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v6-0-7-Has-Been-Released/ba-p/2056522 - Release Notes, Vendor Advisory () https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v6-0-7-Has-Been-Released/ba-p/2056522 - Release Notes, Vendor Advisory
References () https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v8-3-2-Has-Been-Released/ba-p/2049215 - Release Notes, Vendor Advisory () https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v8-3-2-Has-Been-Released/ba-p/2049215 - Release Notes, Vendor Advisory
References () https://hackerone.com/reports/221625 - Third Party Advisory () https://hackerone.com/reports/221625 - Third Party Advisory

Information

Published : 2019-02-12 22:29

Updated : 2024-11-21 03:03


NVD link : CVE-2017-0938

Mitre link : CVE-2017-0938

CVE.ORG link : CVE-2017-0938


JSON object : View

Products Affected

ui

  • airmax_ac
  • airos
  • edgemax
  • edgemax_firmware
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-20

Improper Input Validation