CVE-2023-41721
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/10/2023
Last modified:
10/09/2024
Description
Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.<br />
<br />
Affected Products:<br />
UDM<br />
UDM-PRO<br />
UDM-SE<br />
UDR<br />
UDW<br />
<br />
Mitigation:<br />
Update UniFi Network to Version 7.5.187 or later.<br />
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*:* | 7.5.176 (including) | |
cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ui:unifi_dream_machine_special_edition:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ui:unifi_dream_router:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ui:unifi_dream_wall:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page