CVE-2023-41721

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*:*
OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_special_edition:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_router:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_wall:-:*:*:*:*:*:*:*

History

31 Oct 2023, 20:02

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Ui
Ui unifi Dream Wall
Ui unifi Dream Machine
Ui unifi Network Application
Ui unifi Dream Machine Pro
Ui unifi Dream Router
Ui unifi Dream Machine Special Edition
References (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-036-036/81367bc9-2a64-4435-95dc-bbe482457615 - (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-036-036/81367bc9-2a64-4435-95dc-bbe482457615 - Issue Tracking, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:h:ui:unifi_dream_wall:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_router:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_special_edition:-:*:*:*:*:*:*:*

25 Oct 2023, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-25 18:17

Updated : 2023-12-10 15:14


NVD link : CVE-2023-41721

Mitre link : CVE-2023-41721

CVE.ORG link : CVE-2023-41721


JSON object : View

Products Affected

ui

  • unifi_network_application
  • unifi_dream_machine_special_edition
  • unifi_dream_machine
  • unifi_dream_wall
  • unifi_dream_router
  • unifi_dream_machine_pro