Summary
A malicious actor with access to the network could exploit an improper access control vulnerability in UniFi OS devices to make unauthorized changes to the system. Ubiquiti says the issue affects multiple UniFi OS device families and UniFi OS Server, with fixes released in Security Advisory Bulletin 064. In practice, an attacker could alter device settings and other administrative state without proper authorization.
Why Planned Fix?
4/6Exploitation Details
Make unauthorized changes to device configuration and system state.
Data ManipulationAffected Software
| Product | Affected Versions |
|---|---|
| UCG-Industrial | 5.0.13 and earlier |
| UDM | 5.0.16 and earlier |
| UDM-Pro | 5.0.16 and earlier |
| UDM-SE | 5.0.16 and earlier |
| UDM-Pro-Max | 5.0.16 and earlier |
| EFG | 5.0.16 and earlier |
| UDW | 5.0.16 and earlier |
| UDR | 5.0.16 and earlier |
| UDR7 | 5.0.16 and earlier |
| Express 7 | 5.0.16 and earlier |
| UNVR | 5.0.16 and earlier |
| UNVR-Pro | 5.0.16 and earlier |
| UNVR-Instant | 5.0.16 and earlier |
| ENVR | 5.0.16 and earlier |
| UCG-Ultra | 5.0.16 and earlier |
| UCG-Max | 5.0.16 and earlier |
| UCG-Fiber | 5.0.16 and earlier |
| UDR-5G | 5.0.17 and earlier |
| ENVR-Core | 5.0.17 and earlier |
| UCKP | 5.0.17 and earlier |
| UCK | 5.0.17 and earlier |
| UCK-Enterprise | 5.0.17 and earlier |
| UniFi OS Server | 5.0.6 and earlier |
| UNVR-G2 | 5.1.11 and earlier |
| UNVR-G2-Pro | 5.1.11 and earlier |
| UDM-Beast | 5.1.8 and earlier |
| UNAS-2 | 5.1.8 and earlier |
| UNAS-4 | 5.1.8 and earlier |
| UNAS-Pro | 5.1.8 and earlier |
| UNAS-Pro-4 | 5.1.8 and earlier |
| UNAS-Pro-8 | 5.1.8 and earlier |
Operating system and management platform for UniFi consoles and appliances used to administer networking, storage, and video/security services.
Affected ComponentNetwork-accessible administrative authorization checks in the UniFi OS management interface.
Network-accessible administrative authorization checks in the UniFi OS management interface.
Not available
Not available
Update affected UniFi OS devices to the Security Advisory Bulletin 064 fixed releases: 5.1.12 for most console families, 5.1.10 for UniFi OS Network Attached Storage, 5.1.11 for UDM-Beast, and 5.0.8 for UniFi OS Server.
Update affected UniFi OS devices to the Security Advisory Bulletin 064 fixed releases: 5.1.12 for most console families, 5.1.10 for UniFi OS Network Attached Storage, 5.1.11 for UDM-Beast, and 5.0.8 for UniFi OS Server.
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| community.ui.com | Security Advisory Bulletin 064 |
| community.ui.com | UniFi OS Server 5.0.8 |
| community.ui.com | UniFi OS Cloud Gateways 5.1.12 |
| community.ui.com | UniFi OS Dream Routers 5.1.12 |
| community.ui.com | UniFi OS Express 7 5.1.12 |
| community.ui.com | UniFi OS Network Attached Storage 5.1.10 |
| community.ui.com | UniFi OS Enterprise Network Video Recorders 5.1.12 |
| community.ui.com | UniFi OS Network Video Recorders 5.1.12 |
| community.ui.com | UniFi OS Cloud Keys 5.1.12 |
| community.ui.com | UniFi OS Enterprise Fortress Gateway 5.1.12 |
| community.ui.com | UniFi OS Dream Machines 5.1.12 |
| community.ui.com | UniFi OS Dream Machine Beast 5.1.11 |
| community.ui.com | UniFi OS Dream Wall 5.1.12 |
Priority History
Initial analysis