An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE).
Affected Products:
All UniFi Access Points (Version 6.5.50 and earlier)
All UniFi Switches (Version 6.5.32 and earlier)
-USW Flex Mini excluded.
Mitigation:
Update UniFi Access Points to Version 6.5.62 or later.
Update the UniFi Switches to Version 6.5.59 or later.
References
Link | Resource |
---|---|
https://community.ui.com/releases/Security-Advisory-Bulletin-035-035/91107858-9884-44df-b1c6-63c6499f6e56 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
No history.
Information
Published : 2023-08-10 19:15
Updated : 2023-08-17 14:42
NVD link : CVE-2023-35085
Mitre link : CVE-2023-35085
CVE.ORG link : CVE-2023-35085
JSON object : View
Products Affected
ui
- u6-pro
- us-48-500w
- u6-extender
- u6-lite
- usw-flex-xg
- usw-pro-24-poe
- uap-ac-lite
- uwb-xg
- usw-16-poe
- uap-ac-lr
- ubb
- uap-ac-iw
- usw-enterprise-8-poe
- us-xg-6poe
- usw-pro-aggregation
- us-8-60w
- u6-enterprise
- u6-iw
- usw-48-poe
- usw-mission-critical
- usw-lite-8-poe
- usw-aggregation
- uap-ac-m-pro
- usw-48
- usw-enterprise-24-poe
- ubb-xg
- usw-enterprisexg-24
- usw-24-poe
- uap-ac-pro
- us-8-150w
- usw-24
- usw-flex
- unifi_switch_firmware
- usw-pro-24
- usw-pro-48-poe
- usw-lite-16-poe
- u6\+
- unifi_uap_firmware
- u6-enterprise-iw
- u6-lr
- us-16-150w
- uap-ac-m
- usw-industrial
- usw-enterprise-48-poe
- us-24-250w
- u6-mesh
- usw-pro-48
CWE
CWE-190
Integer Overflow or Wraparound