A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.
References
| Link | Resource |
|---|---|
| https://community.ui.com/releases/Security-Advisory-Bulletin-031-031/8c85fc64-e9a8-4082-9ec4-56b14effd545 | Issue Tracking Vendor Advisory |
| https://community.ui.com/releases/Security-Advisory-Bulletin-031-031/8c85fc64-e9a8-4082-9ec4-56b14effd545 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
12 Dec 2024, 18:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ui unifi Network Application
|
|
| CPE | cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*:* |
21 Nov 2024, 07:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://community.ui.com/releases/Security-Advisory-Bulletin-031-031/8c85fc64-e9a8-4082-9ec4-56b14effd545 - Issue Tracking, Vendor Advisory |
10 Jul 2023, 18:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-031-031/8c85fc64-e9a8-4082-9ec4-56b14effd545 - Issue Tracking, Vendor Advisory | |
| CPE | cpe:2.3:a:ui:unifi:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| CWE | CWE-77 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
03 Jul 2023, 01:10
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-07-01 00:15
Updated : 2024-12-12 18:54
NVD link : CVE-2023-28365
Mitre link : CVE-2023-28365
CVE.ORG link : CVE-2023-28365
JSON object : View
Products Affected
ui
- unifi_network_application
linux
- linux_kernel
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
