PT-2021-15295 · Ubiquiti · Unifi Talk

Published

2021-09-23

·

Updated

2022-08-31

·

CVE-2021-22952

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UniFi Talk application versions 1.12.3 and earlier
Description A vulnerability in the UniFi Talk application permits a malicious actor who has already gained access to a network to control Talk device(s) assigned to said network if they are not yet adopted.
Recommendations For UniFi Talk application versions 1.12.3 and earlier, update to version 1.12.5 or later to resolve the issue.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-22952

Affected Products

Unifi Talk