CVE-2023-28361
CVSS V2 None
CVSS V3 None
Description
A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
Overview
- CVE ID
- CVE-2023-28361
- Assigner
- support@hackerone.com
- Vulnerability Status
- Received
- Published Version
- 2023-05-11T22:15:10
- Last Modified Date
- 2023-05-11T22:15:10
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-28361 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28361 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-05-11 23:00:36 | Added to TrackCVE | |||
2023-05-11 23:00:40 | Weakness Enumeration | new |