CVE-2023-28361

A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:uni:unifi_os:*:*:*:*:*:*:*:*
OR cpe:2.3:h:uni:cloud_key_gen2:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:cloud_key_gen2_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_professional:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_se:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:unifi_dream_router:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:unifi_protect_network_video_recorder:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:unifi_protect_network_video_recorder_professional:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:54

Type Values Removed Values Added
References () https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd - Vendor Advisory () https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd - Vendor Advisory

22 May 2023, 16:42

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Uni cloud Key Gen2
Uni unifi Dream Router
Uni unifi Protect Network Video Recorder
Uni ubiquiti Networks Unifi Dream Machine Professional
Uni unifi Os
Uni
Uni unifi Protect Network Video Recorder Professional
Uni cloud Key Gen2 Plus
Uni ubiquiti Networks Unifi Dream Machine Se
Uni ubiquiti Networks Unifi Dream Machine
References (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd - (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd - Vendor Advisory
CPE cpe:2.3:h:uni:unifi_protect_network_video_recorder:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_se:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:cloud_key_gen2_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_professional:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:unifi_dream_router:-:*:*:*:*:*:*:*
cpe:2.3:o:uni:unifi_os:*:*:*:*:*:*:*:*
cpe:2.3:h:uni:unifi_protect_network_video_recorder_professional:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:cloud_key_gen2:-:*:*:*:*:*:*:*
cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine:-:*:*:*:*:*:*:*

11 May 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-11 22:15

Updated : 2025-01-27 17:15


NVD link : CVE-2023-28361

Mitre link : CVE-2023-28361

CVE.ORG link : CVE-2023-28361


JSON object : View

Products Affected

uni

  • ubiquiti_networks_unifi_dream_machine
  • unifi_dream_router
  • cloud_key_gen2_plus
  • unifi_protect_network_video_recorder_professional
  • ubiquiti_networks_unifi_dream_machine_se
  • unifi_os
  • cloud_key_gen2
  • unifi_protect_network_video_recorder
  • ubiquiti_networks_unifi_dream_machine_professional
CWE
CWE-352

Cross-Site Request Forgery (CSRF)