An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
References
Link | Resource |
---|---|
https://community.ui.com/releases/Security-Advisory-Bulletin-027-027/123e4577-9f00-4777-abe1-64a1d56fee05 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
27 Jun 2023, 13:32
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
04 Jan 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:ui:airfiber_60:-:*:*:*:*:*:*:* cpe:2.3:h:ui:airfiber_60-lr:-:*:*:*:*:*:*:* cpe:2.3:o:ui:airfiber_60-lr_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ui:airfiber_60-hd_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:* cpe:2.3:o:ui:airfiber_gigabeam_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ui:airfiber_60-xg_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ui:airfiber_60_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ui:airfiber_gigabeam:-:*:*:*:*:*:*:* cpe:2.3:o:ui:airmax_ac_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ui:airfiber_60-xg:-:*:*:*:*:*:*:* cpe:2.3:h:ui:airfiber_60-hd:-:*:*:*:*:*:*:* |
|
CWE | CWE-863 | |
References | (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-027-027/123e4577-9f00-4777-abe1-64a1d56fee05 - Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
First Time |
Ui airfiber 60 Firmware
Ui airmax Ac Ui airmax Ac Firmware Ui airfiber 60-hd Ui Ui airfiber 60-xg Firmware Ui airfiber Gigabeam Ui airfiber 60-xg Ui airfiber 60-lr Ui airfiber Gigabeam Firmware Ui airfiber 60-lr Firmware Ui airfiber 60 Ui airfiber 60-hd Firmware |
23 Dec 2022, 16:52
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-12-23 15:15
Updated : 2023-12-10 14:48
NVD link : CVE-2022-44565
Mitre link : CVE-2022-44565
CVE.ORG link : CVE-2022-44565
JSON object : View
Products Affected
ui
- airfiber_60-xg
- airfiber_gigabeam_firmware
- airfiber_60-hd_firmware
- airmax_ac
- airmax_ac_firmware
- airfiber_gigabeam
- airfiber_60
- airfiber_60-hd
- airfiber_60-lr
- airfiber_60-lr_firmware
- airfiber_60-xg_firmware
- airfiber_60_firmware
CWE