CVE-2024-29207

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
07/05/2024
Last modified:
15/04/2026

Description

An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. <br /> <br /> <br /> <br /> Affected Products:<br /> <br /> UniFi Connect Application (Version 3.7.9 and earlier) <br /> <br /> UniFi Connect EV Station (Version 1.1.18 and earlier) <br /> <br /> UniFi Connect EV Station Pro (Version 1.1.18 and earlier)<br /> <br /> UniFi Connect Display (Version 1.9.324 and earlier)<br /> <br /> UniFi Connect Display Cast (Version 1.6.225 and earlier)<br /> <br /> <br /> <br /> Mitigation:<br /> <br /> Update UniFi Connect Application to Version 3.10.7 or later.<br /> <br /> Update UniFi Connect EV Station to Version 1.2.15 or later.<br /> <br /> Update UniFi Connect EV Station Pro to Version 1.2.15 or later.<br /> <br /> Update UniFi Connect Display to Version 1.11.348 or later.<br /> <br /> Update UniFi Connect Display Cast to Version 1.8.255 or later.<br /> <br />