MEDIUM · 5.3

CVE-2023-41721

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a...

Vulnerability Description

Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
UiUnifi Network Application<= 7.5.176
UiUnifi Dream Machine-
UiUnifi Dream Machine Pro-
UiUnifi Dream Machine Special Edition-
UiUnifi Dream Router-
UiUnifi Dream Wall-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-41721?

CVE-2023-41721 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a...

How severe is CVE-2023-41721?

CVE-2023-41721 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-41721?

Check the references section above for vendor advisories and patch information. Affected products include: Ui Unifi Network Application, Ui Unifi Dream Machine, Ui Unifi Dream Machine Pro, Ui Unifi Dream Machine Special Edition, Ui Unifi Dream Router.