Vulnerabilities > CVE-2023-31997 - Unspecified vulnerability in UI Unifi OS 3.1

047910
CVSS 9.0 - CRITICAL
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
ui
critical

Summary

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.

Vulnerable Configurations

Part Description Count
OS
Ui
1
Hardware
Ui
2