Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46ph-452x-f4g5

Опубликовано: 25 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.

Affected Products: UDM UDM-PRO UDM-SE UDR UDW

Mitigation: Update UniFi Network to Version 7.5.187 or later.

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.

Affected Products: UDM UDM-PRO UDM-SE UDR UDW

Mitigation: Update UniFi Network to Version 7.5.187 or later.

EPSS

Процентиль: 47%
0.00239
Низкий

10 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.

EPSS

Процентиль: 47%
0.00239
Низкий

10 Critical

CVSS3

Дефекты

CWE-284