UniFi Network Server Vulnerability Affects Root Escalation
CVE-2024-42025
What is CVE-2024-42025?
A Command Injection vulnerability has been identified in the self-hosted UniFi Network Servers operating on Linux, specifically affecting the UniFi Network Application version 8.3.32 and earlier. This vulnerability permits a malicious actor with 'unifi' user shell access to escalate their privileges to root on the host device, thereby jeopardizing the security and integrity of the entire system. Organizations utilizing affected versions are strongly advised to assess their exposure and apply appropriate mitigations to safeguard their network environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
UniFi Network Application 8.4.59
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
