OVERKILL
$100 Site Donor 2021
A level 10 security flaw has been discovered in Unifi Network Application that allows authentication bypass and account takeover:
https://www.bleepingcomputer.com/ne...-unifi-flaw-that-may-enable-account-takeover/
Unifi Network Application 10.1.85 and earlier are vulnerable, and the 10.2 series with 10.2.93 and earlier. If you are still on 9, the affected releases are 9.0.114 and earlier.
From the article, Unifi's own words:
"A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account,"
Here's the Unifi page:
https://community.ui.com/releases/S...-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b
If you are using modern and supported Unifi products, the default configuration is for them to auto-update at 3:00AM nightly, my UDM-SE is on 10.1.89 already, so I'm already running a patched version.
So, check your stuff!
https://www.bleepingcomputer.com/ne...-unifi-flaw-that-may-enable-account-takeover/
Unifi Network Application 10.1.85 and earlier are vulnerable, and the 10.2 series with 10.2.93 and earlier. If you are still on 9, the affected releases are 9.0.114 and earlier.
From the article, Unifi's own words:
"A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account,"
Here's the Unifi page:
https://community.ui.com/releases/S...-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b
If you are using modern and supported Unifi products, the default configuration is for them to auto-update at 3:00AM nightly, my UDM-SE is on 10.1.89 already, so I'm already running a patched version.
So, check your stuff!