Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gj29-j7qg-vpf7

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point.

Affected Products: UniFi iOS App (Version 10.17.7 and earlier)

Mitigation: UniFi iOS App (Version 10.18.0 or later).

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point.

Affected Products: UniFi iOS App (Version 10.17.7 and earlier)

Mitigation: UniFi iOS App (Version 10.18.0 or later).

EPSS

Процентиль: 23%
0.00075
Низкий

7.1 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 года назад

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App (Version 10.17.7 and earlier) Mitigation: UniFi iOS App (Version 10.18.0 or later).

EPSS

Процентиль: 23%
0.00075
Низкий

7.1 High

CVSS3

Дефекты

CWE-295