Описание
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- Permissions Required
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия до 5.10.21 (включая)
cpe:2.3:a:ui:unifi_controller:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00361
Низкий
8.1 High
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-300
CWE-255
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
EPSS
Процентиль: 58%
0.00361
Низкий
8.1 High
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-300
CWE-255