CVE-2022-22570

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
01/04/2022
Last modified:
09/04/2022

Description

A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ui:ua_lite_firmware:*:*:*:*:*:*:*:* 3.8.31.13 (excluding)
cpe:2.3:h:ui:ua_lite:-:*:*:*:*:*:*:*