MEDIUM · 6.5

CVE-2023-28361

A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a ma...

Vulnerability Description

A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
UniUnifi Os< 3.0.13
UniCloud Key Gen2-
UniCloud Key Gen2 Plus-
UniUbiquiti Networks Unifi Dream Machine-
UniUbiquiti Networks Unifi Dream Machine Professional-
UniUbiquiti Networks Unifi Dream Machine Se-
UniUnifi Dream Router-
UniUnifi Protect Network Video Recorder-
UniUnifi Protect Network Video Recorder Professional-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-28361?

CVE-2023-28361 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a ma...

How severe is CVE-2023-28361?

CVE-2023-28361 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-28361?

Check the references section above for vendor advisories and patch information. Affected products include: Uni Unifi Os, Uni Cloud Key Gen2, Uni Cloud Key Gen2 Plus, Uni Ubiquiti Networks Unifi Dream Machine, Uni Ubiquiti Networks Unifi Dream Machine Professional.