Improper Access Control in UniFi Gateway Console Products by Ubiquiti
CVE-2023-41721

5.3MEDIUM

Key Information:

Vendor

Ubiquiti

Vendor
CVE Published:
25 October 2023

What is CVE-2023-41721?

The UniFi Network Application, used on various UniFi Gateway Consoles, contains an improper access control vulnerability that allows unauthorized devices on the same network to gain access to sensitive configuration information. This issue affects all versions up to 7.5.176, posing a considerable risk as attackers with preexisting network access could exploit this flaw. It is essential for users to upgrade to version 7.5.187 or later to ensure their devices are secure.

Affected Version(s)

UniFi Network Application 7.5.176

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.