A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
| Vendor | Product | Versions |
|---|---|---|
| ubiquiti | unifi os | 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 5.0.6, 5.0.8, 5.1.10, 5.1.11, 5.1.12, 1.61.3, 4.0.14 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| ubiquiti | unifi | cert_advisory | 90% |
Updated affected versions to include 5.0.8 and newer versions, and changed the patch available to 5.1.12.
Updated description with detailed technical information, added affected version 5.0.6, marked exploit as available, and included new IoCs and tags.
Updated affected versions to include 5.0.6 and corrected patch available version to 5.0.6.
Updated affected versions with additional products and marked the vulnerability as actively exploited.
Initial creation