Oct. 25, 2023, 6:17 p.m. |

National Vulnerability Database web.nvd.nist.gov

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.

Affected Products:
UDM
UDM-PRO
UDM-SE
UDR
UDW

Mitigation:
Update UniFi Network to Version 7.5.187 or later.

access access control actor adoption application configuration console control cve device gateway information logic malicious mitigation network pro products risk run unifi update

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Information Security Engineer, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

BaaN IV Techno-functional consultant-On-Balfour

@ Marlabs | Piscataway, US

Senior Security Analyst

@ BETSOL | Bengaluru, India

Security Operations Centre Operator

@ NEXTDC | West Footscray, Australia

Senior Network and Security Research Officer

@ University of Toronto | Toronto, ON, CA