Vulnerabilities > CVE-2014-2226 - Credentials Management vulnerability in UI Unifi Controller

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
high complexity
ui
CWE-255

Summary

Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Ui
4

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/127616/ubiquiti-disclose.txt
idPACKETSTORM:127616
last seen2016-12-05
published2014-07-25
reporterSeth Art
sourcehttps://packetstormsecurity.com/files/127616/Ubiquiti-UbiFi-Controller-2.4.5-Password-Hash-Disclosure.html
titleUbiquiti UbiFi Controller 2.4.5 Password Hash Disclosure