UniFi Network Server Vulnerability Affects Root Escalation
CVE-2024-42025
7.8HIGH
What is CVE-2024-42025?
A Command Injection vulnerability has been identified in the self-hosted UniFi Network Servers operating on Linux, specifically affecting the UniFi Network Application version 8.3.32 and earlier. This vulnerability permits a malicious actor with 'unifi' user shell access to escalate their privileges to root on the host device, thereby jeopardizing the security and integrity of the entire system. Organizations utilizing affected versions are strongly advised to assess their exposure and apply appropriate mitigations to safeguard their network environments.
Affected Version(s)
UniFi Network Application 8.4.59