PT-2020-7622 · Ubiquiti · Unifi Controller

Sethsec

·

Published

2020-02-08

·

Updated

2020-02-12

·

CVE-2014-2225

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions UniFi Controller versions prior to 3.2.1
Description The issue allows remote attackers to hijack the authentication of administrators for various requests, including creating a new admin user, changing guest settings, blocking or unblocking users, and modifying syslog settings. Specifically, the affected API endpoints include "api/add/admin" for creating a new admin user, "api/add/wlanconf" for unspecified impact, "api/set/setting/guest access" for changing guest password, authentication method, or restricted subnets, "api/cmd/stamgr" for blocking, unblocking, or reconnecting users by MAC address, "api/set/setting/rsyslogd" for changing the syslog server or port, "api/set/setting/smtp" for unspecified impact, "api/cmd/cfgmgr" for changing syslog server, port, or authentication settings, and "api/set/setting/identity" for changing the Unifi Controller name.
Recommendations For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoints until a patch is available. Avoid using the vulnerable API endpoints for sensitive operations until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2225

Affected Products

Unifi Controller