PT-2022-1391 · Apache+1 · Log4J+1

Published

2022-01-14

·

Updated

2022-08-09

·

CVE-2021-44530

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UniFi Network versions 6.5.53 and earlier
Description A third-party library injection vulnerability exists due to insufficient input validation in the Java logging library Log4j used in UniFi Network. This issue allows a malicious actor to potentially control the application and execute arbitrary code.
Recommendations For UniFi Network versions 6.5.53 and earlier, update to a version that includes a fix for the Log4j vulnerability to prevent exploitation.

Fix

Special Elements Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-00194
CVE-2021-44530

Affected Products

Log4J
Unifi Network