CVE-2017-0933

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
22/03/2018
Last modified:
09/10/2019

Description

Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled page, allowing the attacker to gain admin privileges in the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ubnt:edgeos:*:*:*:*:*:*:*:* 1.9.1 (including)