CVE-2023-2376는 Ubiquiti EdgeRouter X, er-x firmware, er-x에서 확인된 높음 등급 보안 취약점입니다. 공개 데이터에 표시된 영향 버전은 2.0.9-hotfix.0, 2.0.9-hotfix.1, 2.0.9-hotfix.2, 2.0.9-hotfix.3, 2.0.9-hotfix.4, 2.0.9-hotfix.5, 2.0.9-hotfix.6, < 2.0.9, 2.0.9입니다. CVSS 기본 점수는 7.3점입니다. 현재 CISA KEV 등록은 확인되지 않았습니다.
CVE-2023-2376는 Ubiquiti EdgeRouter X, er-x firmware, er-x에서 확인된 높음 등급 보안 취약점입니다. 공개 데이터에 표시된 영향 버전은 2.0.9-hotfix.0, 2.0.9-hotfix.1, 2.0.9-hotfix.2, 2.0.9-hotfix.3, 2.0.9-hotfix.4, 2.0.9-hotfix.5, 2.0.9-hotfix.6, < 2.0.9, 2.0.9입니다. CVSS 기본 점수는 7.3점입니다. 현재 CISA KEV 등록은 확인되지 않았습니다.
NVD 영문 원문의 세부 내용은 한국어 설명으로 순차 보강 중입니다. 보강 전에는 제품·위험도·실제 악용 여부처럼 공개 데이터로 확인된 정보만 표시합니다.
영문 원문 보기
A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. There are still doubts about whether this vulnerability truly exists. The vendor position is that post-authentication issues are not accepted as vulnerabilities.
영향 제품·버전
제품 Ubiquiti EdgeRouter X, er-x firmware, er-x
영향 버전 Ubiquiti EdgeRouter X, er-x firmware, er-x 2.0.9-hotfix.0, 2.0.9-hotfix.1, 2.0.9-hotfix.2, 2.0.9-hotfix.3, 2.0.9-hotfix.4, 2.0.9-hotfix.5, 2.0.9-hotfix.6, < 2.0.9, 2.0.9
수정 버전 Ubiquiti EdgeRouter X, er-x firmware, er-x 2.0.9
필드별 과거 원문을 추정하지 않습니다. 각 시점의 현재 값과 공식 출처를 대조해 변경 여부를 확인하세요.
기술 정보
CVSS 벡터 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X