CVE-2024-22054

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
20/02/2024
Last modified:
27/03/2025

Description

A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery.<br /> <br /> <br /> Affected Products:<br /> UniFi Access Points<br /> UniFi Switches<br /> UniFi LTE Backup<br /> UniFi Express (Only Mesh Mode, Router mode is not affected)<br /> <br /> <br /> Mitigation:<br /> Update UniFi Access Points to Version 6.6.55 or later.<br /> Update UniFi Switches to Version 6.6.61 or later.<br /> Update UniFi LTE Backup to Version 6.6.57 or later.<br /> Update UniFi Express to Version 3.2.5 or later.