PT-2024-22807 · Google+1 · Android Debug Bridge+7

Published

2024-05-07

·

Updated

2024-07-03

·

CVE-2024-29206

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions UniFi Connect EV Station versions 1.1.18 and earlier UniFi Connect EV Station Pro versions 1.1.18 and earlier UniFi Access G2 Reader Pro versions 1.2.172 and earlier UniFi Access Reader Pro versions 2.7.238 and earlier UniFi Access Intercom versions 1.0.66 and earlier UniFi Access Intercom Viewer versions 1.0.5 and earlier UniFi Connect Display versions 1.9.324 and earlier UniFi Connect Display Cast versions 1.6.225 and earlier
Description An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system.
Recommendations Update UniFi Connect EV Station to Version 1.2.15 or later. Update UniFi Connect EV Station Pro to Version 1.2.15 or later. Update UniFi Access G2 Reader Pro to Version 1.3.37 or later. Update UniFi Access Reader Pro to Version 2.8.19 or later. Update UniFi Access Intercom to Version 1.1.32 or later. Update UniFi Access Intercom Viewer to Version 1.1.6 or later. Update UniFi Connect Display to Version 1.11.348 or later. Update UniFi Connect Display Cast to Version 1.8.255 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-29206
ZDI-24-881

Affected Products

Android Debug Bridge
Unifi Access G2 Reader Pro
Unifi Access Intercom
Unifi Access Intercom Viewer
Unifi Access Reader Pro
Unifi Connect Display
Unifi Connect Display Cast
Unifi Connect Ev Station Pro