PT-2024-22807 · Google+1 · Android Debug Bridge+7
Published
2024-05-07
·
Updated
2024-07-03
·
CVE-2024-29206
CVSS v3.1
2.2
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
UniFi Connect EV Station versions 1.1.18 and earlier
UniFi Connect EV Station Pro versions 1.1.18 and earlier
UniFi Access G2 Reader Pro versions 1.2.172 and earlier
UniFi Access Reader Pro versions 2.7.238 and earlier
UniFi Access Intercom versions 1.0.66 and earlier
UniFi Access Intercom Viewer versions 1.0.5 and earlier
UniFi Connect Display versions 1.9.324 and earlier
UniFi Connect Display Cast versions 1.6.225 and earlier
Description
An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system.
Recommendations
Update UniFi Connect EV Station to Version 1.2.15 or later.
Update UniFi Connect EV Station Pro to Version 1.2.15 or later.
Update UniFi Access G2 Reader Pro to Version 1.3.37 or later.
Update UniFi Access Reader Pro to Version 2.8.19 or later.
Update UniFi Access Intercom to Version 1.1.32 or later.
Update UniFi Access Intercom Viewer to Version 1.1.6 or later.
Update UniFi Connect Display to Version 1.11.348 or later.
Update UniFi Connect Display Cast to Version 1.8.255 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Debug Bridge
Unifi Access G2 Reader Pro
Unifi Access Intercom
Unifi Access Intercom Viewer
Unifi Access Reader Pro
Unifi Connect Display
Unifi Connect Display Cast
Unifi Connect Ev Station Pro