CVE-2022-44565

An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:airfiber_gigabeam_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_gigabeam:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ui:airfiber_60-xg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60-xg:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ui:airfiber_60-hd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60-hd:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ui:airfiber_60-lr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60-lr:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ui:airmax_ac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ui:airfiber_60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60:-:*:*:*:*:*:*:*

History

27 Jun 2023, 13:32

Type Values Removed Values Added
References (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-027-027/123e4577-9f00-4777-abe1-64a1d56fee05 - (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-027-027/123e4577-9f00-4777-abe1-64a1d56fee05 - Patch, Vendor Advisory
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:o:ui:airfiber_60-hd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_60-xg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60-lr:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_gigabeam_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_gigabeam:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60-hd:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_60-lr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_60-xg:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airmax_ac_firmware:*:*:*:*:*:*:*:*

23 Dec 2022, 16:52

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-23 15:15

Updated : 2024-02-04 23:14


NVD link : CVE-2022-44565

Mitre link : CVE-2022-44565

CVE.ORG link : CVE-2022-44565


JSON object : View

Products Affected

ui

  • airfiber_60
  • airfiber_60-hd_firmware
  • airfiber_60-xg_firmware
  • airfiber_60-xg
  • airfiber_60-lr_firmware
  • airmax_ac_firmware
  • airfiber_gigabeam
  • airmax_ac
  • airfiber_60_firmware
  • airfiber_60-hd
  • airfiber_gigabeam_firmware
  • airfiber_60-lr
CWE
NVD-CWE-Other CWE-284

Improper Access Control