PT-2023-3998 · Ubiquiti · Aircube+1

CVE-2023-31998

·

Publicado

2023-05-01

·

Atualizado

2024-10-29

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ubiquiti EdgeRouter versions prior to 2.0.9-hotfix.7 Ubiquiti AirCube versions prior to 2.8.9
Description A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices. The issue is related to the MiniUPnPd service in these devices, which can be exploited by an attacker on the local network to potentially execute arbitrary code. Although there are no signs of this vulnerability being used in real-world attacks, users are recommended to update their devices as soon as possible.
Recommendations For Ubiquiti EdgeRouter versions prior to 2.0.9-hotfix.7, update to version 2.0.9-hotfix.7 or later. For Ubiquiti AirCube versions prior to 2.8.9, update to version 2.8.9 or later. As a temporary workaround, consider disabling the MiniUPnPd service until a patch is available. Restrict access to the UPnP service to minimize the risk of exploitation.

Correção

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04296
CVE-2023-31998

Produtos afetados

Aircube
Edgerouter X