Summary
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. The flaw appears to be unauthenticated and requires no user interaction, affecting multiple UniFi OS appliance families.
Why Planned Fix?
4/6Exploitation Details
Read and modify files on the underlying system to access an underlying account.
Privilege EscalationAffected Software
| Product | Affected Versions |
|---|---|
| UCG-Industrial | 5.0.13 and earlier |
| UDM | 5.0.16 and earlier |
| UDM-Pro | 5.0.16 and earlier |
| UDM-SE | 5.0.16 and earlier |
| UDM-Pro-Max | 5.0.16 and earlier |
| EFG | 5.0.16 and earlier |
| UDW | 5.0.16 and earlier |
| UDR | 5.0.16 and earlier |
| UDR7 | 5.0.16 and earlier |
| Express 7 | 5.0.16 and earlier |
| UNVR | 5.0.16 and earlier |
| UNVR-Pro | 5.0.16 and earlier |
| UNVR-Instant | 5.0.16 and earlier |
| ENVR | 5.0.16 and earlier |
| UCG-Ultra | 5.0.16 and earlier |
| UCG-Max | 5.0.16 and earlier |
| UCG-Fiber | 5.0.16 and earlier |
| UDR-5G | 5.0.17 and earlier |
| ENVR-Core | 5.0.17 and earlier |
| UCKP | 5.0.17 and earlier |
| UCK | 5.0.17 and earlier |
| UCK-Enterprise | 5.0.17 and earlier |
| UniFi OS Server | 5.0.6 and earlier |
| UNVR-G2 | 5.1.11 and earlier |
| UNVR-G2-Pro | 5.1.11 and earlier |
| UDM-Beast | 5.1.8 and earlier |
| UNAS-2 | 5.1.8 and earlier |
| UNAS-4 | 5.1.8 and earlier |
| UNAS-Pro | 5.1.8 and earlier |
| UNAS-Pro-4 | 5.1.8 and earlier |
| UNAS-Pro-8 | 5.1.8 and earlier |
Operating system that powers Ubiquiti UniFi network appliances such as gateways, consoles, network video recorders, and storage devices.
Affected ComponentFile path handling in the UniFi OS web management interface.
File path handling in the UniFi OS web management interface.
Not available
Not available
Upgrade affected UniFi OS devices to the fixed releases in Security Advisory Bulletin 064: 5.1.12 or later for most gateway/controller families, 5.0.8 or later for UniFi OS Server, 5.1.10 or later for UNAS devices, and 5.1.11 or later for UDM-Beast.
Upgrade affected UniFi OS devices to the fixed releases in Security Advisory Bulletin 064: 5.1.12 or later for most gateway/controller families, 5.0.8 or later for UniFi OS Server, 5.1.10 or later for UNAS devices, and 5.1.11 or later for UDM-Beast.
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| community.ui.com | Security Advisory Bulletin 064 |
Priority History
Initial analysis