PT-2023-21672 · Ubiquiti · Unifi Os

CVE-2023-28361

·

Published

2023-05-11

·

Updated

2023-05-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions UniFi OS versions 2.5 and earlier
Description A Cross-site WebSocket Hijacking (CSWSH) issue allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage. The affected products include Cloud Key Gen2, Cloud Key Gen2 Plus, UNVR, UNVR Professional, UDM, UDM Professional, UDM SE, and UDR.
Recommendations Update affected products to UniFi OS 3.0.13 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28361

Affected Products

Unifi Os