PT-2023-21672 · Ubiquiti · Unifi Os
CVE-2023-28361
·
Published
2023-05-11
·
Updated
2023-05-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
UniFi OS versions 2.5 and earlier
Description
A Cross-site WebSocket Hijacking (CSWSH) issue allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage. The affected products include Cloud Key Gen2, Cloud Key Gen2 Plus, UNVR, UNVR Professional, UDM, UDM Professional, UDM SE, and UDR.
Recommendations
Update affected products to UniFi OS 3.0.13 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unifi Os