Misconfiguration in UniFi Network Affects UniFi OS 3.1 and Cloud Key Devices
CVE-2023-31997
9CRITICAL
What is CVE-2023-31997?
A misconfiguration issue exists in UniFi OS 3.1 that enables unauthorized access to MongoDB by users on the same local network. This affects certain Cloud Key models when hosting the UniFi Network application, specifically Cloud Key Gen2 and Cloud Key Gen2 Plus. Users should ensure that proper configurations are in place to prevent unauthorized access.
Affected Version(s)
UniFi OS 3.1.13