Vulnerabilities > UI

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2017-0912 Cross-site Scripting vulnerability in UI Ucrm
Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting.
network
ui CWE-79
3.5
2018-06-20 CVE-2018-12590 Use of Externally-Controlled Format String vulnerability in UI Edgeswitch Firmware 1.7.3
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater than administrators themselves are allowed.
network
low complexity
ui CWE-134
critical
9.0
2018-03-22 CVE-2017-0935 Improper Privilege Management vulnerability in UI Edgeos 1.9.1/1.9.1.1
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed.
network
low complexity
ui CWE-269
critical
9.0
2017-12-27 CVE-2016-6914 Incorrect Default Permissions vulnerability in UI Unifi Video
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
local
low complexity
ui CWE-276
7.2
2014-07-29 CVE-2014-2226 Credentials Management vulnerability in UI Unifi Controller
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
network
high complexity
ui CWE-255
2.6
2014-07-25 CVE-2014-2227 Permissions, Privileges, and Access Controls vulnerability in UI Unifi Video 2.1.3
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.
network
ui CWE-264
6.0
2013-07-18 CVE-2013-1606 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in UI products
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allows remote attackers to execute arbitrary code via a long rtsp: URI in a DESCRIBE request.
network
low complexity
ui CWE-119
7.5