CVE-2019-16889-poc exploit

Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.

Published 25 Sep 2019Updated 17 Jun 20269 sources
CVSS 7.5 ✓ VERIFIED REFERENCE

Source timeline

Discovered through SploitusView source ↗
CVE record published by NVDView source ↗