Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.
Affected Products:
UDM
UDM-PRO
UDM-SE
UDR
UDW
Mitigation:
Update UniFi Network to Version 7.5.187 or later.
References
Link | Resource |
---|---|
https://community.ui.com/releases/Security-Advisory-Bulletin-036-036/81367bc9-2a64-4435-95dc-bbe482457615 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2023-10-25 18:17
Updated : 2023-10-31 20:02
NVD link : CVE-2023-41721
Mitre link : CVE-2023-41721
CVE.ORG link : CVE-2023-41721
JSON object : View
Products Affected
ui
- unifi_dream_machine_special_edition
- unifi_dream_router
- unifi_dream_wall
- unifi_network_application
- unifi_dream_machine
- unifi_dream_machine_pro
CWE