CVE-2024-22054
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
20/02/2024
Last modified:
27/03/2025
Description
A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery.<br />
<br />
<br />
Affected Products:<br />
UniFi Access Points<br />
UniFi Switches<br />
UniFi LTE Backup<br />
UniFi Express (Only Mesh Mode, Router mode is not affected)<br />
<br />
<br />
Mitigation:<br />
Update UniFi Access Points to Version 6.6.55 or later.<br />
Update UniFi Switches to Version 6.6.61 or later.<br />
Update UniFi LTE Backup to Version 6.6.57 or later.<br />
Update UniFi Express to Version 3.2.5 or later.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



