Unverified Password Change Vulnerability in UniFi Connect Products by Ubiquiti
CVE-2024-29208
2.2LOW
What is CVE-2024-29208?
A security flaw exists in Ubiquiti's UniFi Connect products that allows unauthorized password alterations via API access. This vulnerability could enable malicious actors to change system passwords without needing the original password, compromising device security. Users are advised to update their affected products promptly to mitigate the risk.
Affected Version(s)
Update UniFi Connect Display 1.11.348
Update UniFi Connect Display Cast 1.8.255
Update UniFi Connect EV Station 1.2.15
References
CVSS V3.1
Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
