+ Product
+ Solution
Pricing
+ Resources
+ Company
Research Center Contact
Login
Start Free Trial
Research Center
CVE-2020-8234 Research Center
topia vulnerability management banner 11.png

CVE-2020-8234

A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.

  • 9.8 critical severity
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • 21/08/2020

Operating Systems 11

EP

EP-S16

by UI

1 Version

8 months ago

ES

ES-12F

by UI

1 Version

8 months ago

Es

Es-16-150w

by UI

1 Version

8 months ago

ES

ES-16-XG

by UI

1 Version

8 months ago

Es

Es-24-250w

by UI

1 Version

8 months ago

Es

Es-24-500w

by UI

1 Version

8 months ago

Es

Es-24-Lite

by UI

1 Version

8 months ago

Es

Es-48-500w

by UI

1 Version

8 months ago

Es

Es-48-750w

by UI

1 Version

8 months ago

Es

Es-48-Lite

by UI

1 Version

8 months ago

Vulnerability Categories 1

Insufficient Session Expiration

Patch Links 1

https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821,

Advisory Links 3

https://www.ui.com/download/edgemax
https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695c,
https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821,
http://www.vicarius.io is owned and operated by Vicarius Ltd. (the “Company”). All information contained on the Website is purely for informational, and educational purposes and should be independently verified and confirmed. Vicarius does not accept any liability for any loss or damage whatsoever caused in reliance upon such information or services. No statements or information presented in any form by Vicarius is intended as fact, and you agree that you will not consider the statements or information presented on the Website as fact or as a guarantee of performance.

Related CVEs

Security Research Topics

By Kent Weigle
Mar 10, 2021

February Trending CVEs: CVE-2021-3156

As stewards of the lush and vast landscape of security vulnerabilities, we felt obliged to share with you the top trending CVEs of the past month (who's excited for winter to be over?! đŸ˜â˜€ď¸đŸŒˇ). Brace yourself! Ok, here we go.

By Kent Weigle
Mar 10, 2021

February Trending CVEs: CVE-2020-1472

As stewards of the lush and vast landscape of security vulnerabilities, we felt obliged to share with you the top trending CVEs of the past month (who's excited for winter to be over?! đŸ˜â˜€ď¸đŸŒˇ). Brace yourself! Ok, here we go.

By Kent Weigle
Mar 10, 2021

February Trending CVEs: CVE-2021-24078

As stewards of the lush and vast landscape of security vulnerabilities, we felt obliged to share with you the top trending CVEs of the past month (who's excited for winter to be over?! đŸ˜â˜€ď¸đŸŒˇ). Brace yourself! Ok, here we go.

By Kent Weigle
Feb 01, 2021

Top Trending CVEs of January 2021

Well, we made it through the first month of 2021! (Hopefully without any scratches or bruises 😅). As stewards of the lush and vast landscape of security vulnerabilities, we felt obliged to share with you the top trending CVEs of the past month. So, without further ado, The Top Trending CVEs of January 2021:

By Kent Weigle
Dec 22, 2020

Security Vulnerability Examples

As the threat landscape changes, the ability to address the most common types of security vulnerabilities is vital for robust protection. As information becomes the most essential asset for an organization, cybersecurity gains much more importance. To successfully conduct your business and preserve the hard-earned reputation of your company, you need to protect your data from malicious attacks, data breaches and hackers. 

By Kent Weigle
Dec 22, 2020

Zoom Security Vulnerabilities

As if times haven’t been hard enough, businesses are dealing with new security threats while employees work from home and some have major issues with one of the most popular video conferencing platforms, Zoom.

By Kent Weigle
Dec 22, 2020

What is a Vulnerability?

This article will offer a quick guide to vulnerabilities – what they are, how they can be exploited and the consequences of exploitation. A vulnerability is a weakness in an asset that can be exploited by cyber attackers. It’s a known issue that allows an attack to succeed. 

By Kent Weigle
Dec 21, 2020

Top 10 Software Vulnerabilities

Security testing is an assessment of the sensitivity of a software vulnerability to various attacks. What type of attacks? Mainly unauthorized breaches into the system with the aim of extracting data about users or getting confidential information. With the help of vulnerabilities present in the software code, attackers can achieve their objectives.  

By Kent Weigle
Dec 21, 2020

Zero-Day Vulnerability: Defense Strategies

A zero-day is a weakness in hardware, software or firmware that is not known to the parties responsible for patching or fixing the flaw. The term zero refers to an attack that has zero days between the time the vulnerability is discovered and the first attack. Once a zero-day vulnerability is known to the public, it’s known as a one-day or n-day vulnerability.

last chance_02.png

Start Closing Security Gaps

  • Risk reduction from Day 1
  • Fast set-up and deployment
  • Unified platform
  • Full-featured 30-day trial
Schedule Live Demo!
Start Free Trial Now

Have questions?

By submitting this form, you agree to be contacted about TOPIA and other Vicarius products.

TOPIA is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.
We're hiring!

Support

support@vicarius.io

Sales

sales@vicarius.io

Marketing

info@vicarius.io
Product
Product Overview
Patch Management
Patchless Protection
xTags
0-Day Detection
Solution
Solution Overview
Case Studies
Resources
Webinars
Blog
Partners
Downloads
Company
About
News
Investors
Careers
Pricing
Pricing
Research Center
Research Center
Supported Apps and OS

Copyright Š Vicarius. All rights reserved 2020. Privacy Policy and Terms of Use