Vulnerability Description
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Unifi Controller | <= 5.10.21 |
Related Weaknesses (CWE)
References
- https://community.ui.com/releases/862b962b-55f6-4324-96be-610f647d5c1cRelease NotesVendor Advisory
- https://community.ui.com/releases/9f698d0b-8279-40d3-9f1a-d36db4813124Release NotesVendor Advisory
- https://community.ui.com/releases/Security-Advisory-Bulletin-003-003/982bbaa8-2aVendor Advisory
- https://hackerone.com/reports/519582Permissions Required
- https://community.ui.com/releases/862b962b-55f6-4324-96be-610f647d5c1cRelease NotesVendor Advisory
- https://community.ui.com/releases/9f698d0b-8279-40d3-9f1a-d36db4813124Release NotesVendor Advisory
- https://community.ui.com/releases/Security-Advisory-Bulletin-003-003/982bbaa8-2aVendor Advisory
- https://hackerone.com/reports/519582Permissions Required
FAQ
What is CVE-2019-5456?
CVE-2019-5456 is a vulnerability with a CVSS score of 8.1 (HIGH). SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use la...
How severe is CVE-2019-5456?
CVE-2019-5456 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5456?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Unifi Controller.