UniFi Network Server Vulnerability Affects Root Escalation
CVE-2024-42025

7.8HIGH

Key Information:

Vendor
Ubiquiti Inc
Status
Unifi Network Application
Vendor
CVE Published:
13 September 2024

Summary

A Command Injection vulnerability has been identified in the self-hosted UniFi Network Servers operating on Linux, specifically affecting the UniFi Network Application version 8.3.32 and earlier. This vulnerability permits a malicious actor with 'unifi' user shell access to escalate their privileges to root on the host device, thereby jeopardizing the security and integrity of the entire system. Organizations utilizing affected versions are strongly advised to assess their exposure and apply appropriate mitigations to safeguard their network environments.

Affected Version(s)

UniFi Network Application 8.4.59

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.