Vulnerabilities > UI > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-18 CVE-2023-31998 Out-of-bounds Write vulnerability in UI Aircube Firmware and Edgemax Edgerouter Firmware
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.
network
low complexity
ui CWE-787
7.5
2023-04-28 CVE-2023-2379 Improper Resource Shutdown or Release vulnerability in UI Er-X-Sfp Firmware and Er-X Firmware
A vulnerability classified as critical has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6.
network
low complexity
ui CWE-404
7.5
2023-04-28 CVE-2023-2376 Command Injection vulnerability in UI Er-X-Sfp Firmware and Er-X Firmware
A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6.
network
low complexity
ui CWE-77
8.8
2023-04-28 CVE-2023-2377 Command Injection vulnerability in UI Er-X-Sfp Firmware and Er-X Firmware
A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6.
network
low complexity
ui CWE-77
8.8
2023-04-28 CVE-2023-2378 Command Injection vulnerability in UI Er-X-Sfp Firmware and Er-X Firmware
A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6.
network
low complexity
ui CWE-77
8.8
2023-04-28 CVE-2023-2374 Command Injection vulnerability in UI Er-X-Sfp Firmware and Er-X Firmware
A vulnerability has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6 and classified as critical.
network
low complexity
ui CWE-77
8.8
2023-04-28 CVE-2023-2375 Command Injection vulnerability in UI Er-X-Sfp Firmware and Er-X Firmware
A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6 and classified as critical.
network
low complexity
ui CWE-77
8.8
2023-04-28 CVE-2023-2373 Command Injection vulnerability in UI Edgemax Edgerouter Firmware 2.0.9
A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6.
network
low complexity
ui CWE-77
8.8
2023-04-19 CVE-2023-28122 Unspecified vulnerability in UI Desktop 0.55.1.2/0.55.3.17
A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access to a Windows device running said application to submit arbitrary commands as SYSTEM.This vulnerability is fixed in Version 0.62.3 and later.
local
low complexity
ui
7.8
2023-02-09 CVE-2023-23912 Code Injection vulnerability in UI products
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.
low complexity
ui CWE-94
8.8