Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rj5-gh6q-72fp

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. 

Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31).

Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. 

Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31).

Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

EPSS

Процентиль: 93%
0.10557
Средний

10 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 10
nvd
3 месяца назад

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVSS3: 10
fstec
4 месяца назад

Уязвимость системы контроля доступа UniFi Access, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить полный контроль над системой

EPSS

Процентиль: 93%
0.10557
Средний

10 Critical

CVSS3

Дефекты

CWE-306