Vulnerabilities > UI
|2020-12-14||CVE-2020-8282|| Cross-Site Request Forgery (CSRF) vulnerability in UI products |
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.
| 6.8 |
|2020-11-05||CVE-2020-8267|| Improper Authentication vulnerability in UI Unifi Protect Firmware |
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated messages without a valid token.This vulnerability was fixed in UniFi Protect v1.14.11 and newer.This issue does not impact UniFi Cloud Key Gen 2 plus.This issue does not impact UDM-Pro customers with UniFi Protect stopped.Affected Products:UDM-Pro firmware 1.7.2 and earlier.UNVR firmware 1.3.12 and earlier.Mitigation:Update UniFi Protect to v1.14.11 or newer version; the UniFi Protect controller can be updated through your UniFi OS settings.Alternatively, you can update UNVR and UDM-Pro to:- UNVR firmware to 1.3.15 or newer.- UDM-Pro firmware to 1.8.0 or newer.
| 5.0 |
|2020-10-27||CVE-2020-27888|| Insufficiently Protected Credentials vulnerability in UI products |
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 126.96.36.19925 and UniFi Controller 6.0.28 devices.
| 5.0 |
|2020-08-21||CVE-2020-8234|| Insufficient Session Expiration vulnerability in UI Edgemax Firmware |
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.
| 10.0 |
|2020-08-17||CVE-2020-8233|| OS Command Injection vulnerability in UI Edgeswitch Firmware 1.7.1 |
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
| 9.0 |
|2020-08-17||CVE-2020-8232|| Information Exposure vulnerability in UI Edgeswitch Firmware 1.7.1 |
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
| 4.0 |
|2020-07-30||CVE-2020-8213|| Information Exposure Through AN Error Message vulnerability in UI Unifi Protect 1.13.3 |
An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing.
| 5.0 |
|2020-07-02||CVE-2020-8188|| OS Command Injection vulnerability in UI Unifi Protect Firmware |
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prior according to the description below:View only users can run certain custom commands which allows them to assign themselves unauthorized roles and escalate their privileges.
| 6.5 |
|2020-06-08||CVE-2020-12695|| Incorrect Default Permissions vulnerability in multiple products |
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
| 7.8 |
|2020-05-26||CVE-2020-8171|| OS Command Injection vulnerability in UI Airos |
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that are vulnerable to command injection.
| 7.5 |