PT-2023-28063 · Ubiquiti · Udm-Pro+5

Published

2023-10-23

·

Updated

2024-09-10

·

CVE-2023-41721

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UniFi Network versions 7.5.176 and earlier UDM versions prior to 7.5.187 UDM-PRO versions prior to 7.5.187 UDM-SE versions prior to 7.5.187 UDR versions prior to 7.5.187 UDW versions prior to 7.5.187
Description The issue is related to improper access control logic in device adoption, which creates a risk of access to device configuration information by a malicious actor with preexisting access to the network. This affects instances of UniFi Network Application run on a UniFi Gateway Console.
Recommendations Update UniFi Network to Version 7.5.187 or later. As a temporary workaround, consider restricting access to the UniFi Gateway Console until the update is applied. For UDM, UDM-PRO, UDM-SE, UDR, and UDW devices, update to version 7.5.187 or later to mitigate the risk. If automatic updates are not enabled, manually update the devices to version 7.5.187 or later as soon as possible.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-41721

Affected Products

Udm
Udm-Pro
Udm-Se
Udr
Udw
Unifi Network