Vulnerability Description
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Unifi Os | 3.1 |
| Ui | Cloud Key Gen2 | - |
| Ui | Cloud Key Gen2 Plus | - |
Related Weaknesses (CWE)
References
- https://community.ui.com/releases/Security-Advisory-Bulletin-032-032/e57301f4-4fIssue Tracking
- https://community.ui.com/releases/Security-Advisory-Bulletin-032-032/e57301f4-4fIssue Tracking
FAQ
What is CVE-2023-31997?
CVE-2023-31997 is a vulnerability with a CVSS score of 9.0 (CRITICAL). UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2...
How severe is CVE-2023-31997?
CVE-2023-31997 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-31997?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Unifi Os, Ui Cloud Key Gen2, Ui Cloud Key Gen2 Plus.