Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3gj-969x-5q5x

Опубликовано: 20 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery.

Affected Products:

UniFi Access Points

UniFi Switches

UniFi LTE Backup

UniFi Express (Only Mesh Mode, Router mode is not affected)

Mitigation:

Update UniFi Access Points to Version 6.6.65 or later.

Update UniFi Switches to Version 6.6.61 or later.

Update UniFi LTE Backup to Version 6.6.57 or later.

Update UniFi Express to Version 3.2.5 or later.

A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery.

Affected Products:

UniFi Access Points

UniFi Switches

UniFi LTE Backup

UniFi Express (Only Mesh Mode, Router mode is not affected)

Mitigation:

Update UniFi Access Points to Version 6.6.65 or later.

Update UniFi Switches to Version 6.6.61 or later.

Update UniFi LTE Backup to Version 6.6.57 or later.

Update UniFi Express to Version 3.2.5 or later.

EPSS

Процентиль: 21%
0.00069
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi Access Points to Version 6.6.55 or later. Update UniFi Switches to Version 6.6.61 or later. Update UniFi LTE Backup to Version 6.6.57 or later. Update UniFi Express to Version 3.2.5 or later.

EPSS

Процентиль: 21%
0.00069
Низкий

7.5 High

CVSS3

Дефекты

CWE-20