← back
CVE-2019-5426

CVE-2019-5426

EPSS 0.8%CWE-287
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Apr 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →