CVE-2023-28365

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
01/07/2023
Last modified:
12/12/2024

Description

A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*:* 7.4.156 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*