- HostiFi
- Posts
- Security update going out today
Security update going out today
Hi guys!
Reilly here.
UniFi OS, UniFi Protect, and UniFi Talk each have a 10 score CVE allowing full takeover without auth.
We are pushing the UniFi OS Server and UniFi Network updates to all of our customers immediately, following a short testing period to ensure there will be zero downtime for any of your networks.
If you have any self-hosted servers out there that you’d like assistance with updating you can submit a ticket to work with our professional services team at hostifi.com/pro
If you have any questions you can reply to this email to reach our support team or if you’d like to speak with me specifically you can email me at [email protected] or call me on my direct line +1 866 503-7935
Here’s a summarized list of all the new vulnerabilities:
UniFi OS (Server 5.1.21 → 5.1.37; consoles 5.1.26 → 5.1.31; NAS 5.1.32)
10.0 Critical — CRLF bug, no login, bypasses auth
9.9 Critical — low-priv access control, escalate on the device
9.9 Critical — low-priv access control, escalate on the device
9.1 Critical — admin command injection on UOS Server
9.1 Critical — admin command injection on UOS Server
9.0 Critical — leftover debug code, escalate under some conditions
9.0 Critical — CRLF bug under some conditions
UniFi Network (10.4.57 → 10.5.67)
9.1 Critical — admin command injection on an adopted device
9.1 Critical — admin access control, escalate inside Network
UniFi Protect (7.1.87 → 7.2.105)
10.0 Critical — no login, command injection on the host
9.9 Critical — low-priv command injection on the host
9.9 Critical — low-priv command injection on the host
UniFi Talk (5.2.7 → 5.3.2)
10.0 Critical — no login, command injection on the host
UniFi Access (4.3.3 → 4.3.5)
9.9 Critical — low-priv command injection
9.9 Critical — low-priv command injection
9.9 Critical — low-priv command injection
9.9 Critical — low-priv access control, take over the host
UniFi Enterprise Audio/Video Bridge (1.0.10 → 1.0.11)
9.8 Critical — no login, command injection on the device
UniFi Protect AI Key (2.1.3 → 2.2.6)
9.8 Critical — no login, privilege escalate on the device
UID Enterprise Agent (1.61.8 → 1.62.1)
9.1 Critical — admin command injection
UniFi Connect Display Cast Pro (1.0.108 → 1.0.111)
9.0 Critical — access control, escalate under some conditions
UniFi Connect (3.24.20 → 3.24.22)
8.2 High — no login, escalate inside Connect (can chain to the host)