CVE-2024-45205
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
04/12/2024
Last modified:
04/12/2024
Description
An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point.<br />
<br />
<br />
Affected Products:<br />
UniFi iOS App (Version 10.17.7 and earlier) <br />
<br />
Mitigation:<br />
UniFi iOS App (Version 10.18.0 or later).
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH