CVE-2023-41721

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/10/2023
Last modified:
10/09/2024

Description

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.<br /> <br /> Affected Products:<br /> UDM<br /> UDM-PRO<br /> UDM-SE<br /> UDR<br /> UDW<br /> <br /> Mitigation:<br /> Update UniFi Network to Version 7.5.187 or later.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*:* 7.5.176 (including)
cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_special_edition:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_router:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_wall:-:*:*:*:*:*:*:*