An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE).
 
Affected Products:
All UniFi Access Points (Version 6.5.50 and earlier)
All UniFi Switches (Version 6.5.32 and earlier) 
-USW Flex Mini excluded.
 
Mitigation:
Update UniFi Access Points to Version 6.5.62 or later.
Update the UniFi Switches to Version 6.5.59 or later.
                
            References
                    | Link | Resource | 
|---|---|
| https://community.ui.com/releases/Security-Advisory-Bulletin-035-035/91107858-9884-44df-b1c6-63c6499f6e56 | Issue Tracking Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2023-08-10 19:15
Updated : 2023-08-17 14:42
NVD link : CVE-2023-35085
Mitre link : CVE-2023-35085
CVE.ORG link : CVE-2023-35085
JSON object : View
Products Affected
                ui
- u6-pro
 - us-48-500w
 - u6-extender
 - u6-lite
 - usw-flex-xg
 - usw-pro-24-poe
 - uap-ac-lite
 - uwb-xg
 - usw-16-poe
 - uap-ac-lr
 - ubb
 - uap-ac-iw
 - usw-enterprise-8-poe
 - us-xg-6poe
 - usw-pro-aggregation
 - us-8-60w
 - u6-enterprise
 - u6-iw
 - usw-48-poe
 - usw-mission-critical
 - usw-lite-8-poe
 - usw-aggregation
 - uap-ac-m-pro
 - usw-48
 - usw-enterprise-24-poe
 - ubb-xg
 - usw-enterprisexg-24
 - usw-24-poe
 - uap-ac-pro
 - us-8-150w
 - usw-24
 - usw-flex
 - unifi_switch_firmware
 - usw-pro-24
 - usw-pro-48-poe
 - usw-lite-16-poe
 - u6\+
 - unifi_uap_firmware
 - u6-enterprise-iw
 - u6-lr
 - us-16-150w
 - uap-ac-m
 - usw-industrial
 - usw-enterprise-48-poe
 - us-24-250w
 - u6-mesh
 - usw-pro-48
 
CWE
                
                    
                        
                        CWE-190
                        
            Integer Overflow or Wraparound
