PT-2023-21672 · Ubiquiti · Unifi Os

CVE-2023-28361

·

Publicado

2023-05-11

·

Atualizado

2023-05-22

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions UniFi OS versions 2.5 and earlier
Description A Cross-site WebSocket Hijacking (CSWSH) issue allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage. The affected products include Cloud Key Gen2, Cloud Key Gen2 Plus, UNVR, UNVR Professional, UDM, UDM Professional, UDM SE, and UDR.
Recommendations Update affected products to UniFi OS 3.0.13 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28361

Produtos afetados

Unifi Os