Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9chj-jjcm-3mr7

Опубликовано: 01 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.

EPSS

Процентиль: 11%
0.00036
Низкий

9 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9
nvd
больше 2 лет назад

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.

EPSS

Процентиль: 11%
0.00036
Низкий

9 Critical

CVSS3

Дефекты

CWE-863