Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-41721

Опубликовано: 25 окт. 2023
Источник: nvd
CVSS3: 10
CVSS3: 5.3
EPSS Низкий

Описание

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.

Affected Products: UDM UDM-PRO UDM-SE UDR UDW

Mitigation: Update UniFi Network to Version 7.5.187 or later.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*:*
Версия до 7.5.176 (включая)

Одно из

cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_special_edition:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_router:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_wall:-:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00239
Низкий

10 Critical

CVSS3

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-284

Связанные уязвимости

CVSS3: 10
github
больше 2 лет назад

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.

EPSS

Процентиль: 47%
0.00239
Низкий

10 Critical

CVSS3

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-284