2023-05-12 02:00:26 +02:00
{
"id" : "CVE-2023-28361" ,
"sourceIdentifier" : "support@hackerone.com" ,
"published" : "2023-05-11T22:15:10.187" ,
2025-01-27 19:03:53 +00:00
"lastModified" : "2025-01-27T17:15:12.240" ,
2024-12-08 03:06:42 +00:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-05-12 02:00:26 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later."
}
] ,
2023-05-22 18:00:46 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
2023-05-22 18:00:46 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-05-22 18:00:46 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
2025-01-27 19:03:53 +00:00
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
2023-05-22 18:00:46 +00:00
}
]
} ,
2023-05-12 02:00:26 +02:00
"weaknesses" : [
2023-05-22 18:00:46 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "support@hackerone.com" ,
"type" : "Secondary" ,
2023-05-22 18:00:46 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-352"
}
]
} ,
2023-05-12 02:00:26 +02:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-05-12 02:00:26 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-352"
}
]
2025-01-27 19:03:53 +00:00
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-352"
}
]
2023-05-12 02:00:26 +02:00
}
] ,
2023-05-22 18:00:46 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
2024-12-08 03:06:42 +00:00
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:uni:unifi_os:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "3.0.13" ,
"matchCriteriaId" : "484887CC-286A-4C59-854A-06616BF3198B"
}
]
} ,
2023-05-22 18:00:46 +00:00
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:cloud_key_gen2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "48EFCCAA-76C0-417B-BCED-BB6C9D0CBE8B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:cloud_key_gen2_plus:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1F171730-7AD1-46B3-ADAF-27BD69E7CC88"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3BF09341-2DD2-4DCF-AEEA-67A6AEF2F0C5"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_professional:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F8E72337-FAB2-4AB3-A8F8-7D32A1CEB17A"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_se:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "ED78B144-E2FE-4648-BAD9-5079C0FB6255"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:unifi_dream_router:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8A6CDD1F-DA20-4199-8D2D-60066D83D538"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:unifi_protect_network_video_recorder:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "27F9EEC7-3D49-4FB0-8CD0-94CAB5651DE0"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:uni:unifi_protect_network_video_recorder_professional:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8E263DAE-C5DB-4642-9CA9-B56C098C8A1E"
}
]
}
]
}
] ,
2023-05-12 02:00:26 +02:00
"references" : [
{
"url" : "https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd" ,
2023-05-22 18:00:46 +00:00
"source" : "support@hackerone.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-05-12 02:00:26 +02:00
}
]
}