By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Ubiquiti Patches Three Maximum Severity Security Vulnerabilities
Ubiquiti has released security patches for three newly identified maximum-severity vulnerabilities that pose a significant risk to users of its networking and surveillance products. These vulnerabilities can be exploited by threat actors remotely and without requiring any prior authentication or privileges, making them particularly dangerous. The company has issued urgent advisories and patches to address these critical security flaws, urging customers to update their systems promptly to mitigate potential exploitation.
The first vulnerability, identified as CVE-2024-22234, is a command injection flaw within the UniFi Network Application. This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system of the affected UniFi Network Application server. The successful exploitation of this flaw could lead to a complete compromise of the server, enabling attackers to gain unauthorized access, steal sensitive data, or disrupt network operations. Ubiquiti's advisory indicates that this vulnerability affects versions prior to 7.4.156 of the UniFi Network Application.
The second critical vulnerability, CVE-2024-22235, is also a command injection issue, but it resides within the UniFi Protect application. Similar to the first, this flaw enables an unauthenticated remote attacker to inject and execute arbitrary commands on the server hosting the UniFi Protect application. This could result in a full system compromise, allowing attackers to control surveillance systems, access recorded footage, or deploy malicious software. This vulnerability impacts versions prior to 2.11.4 of the UniFi Protect application.
The third vulnerability, CVE-2024-22236, is a cross-site scripting (XSS) vulnerability present in the UniFi Network Application. This flaw allows an unauthenticated remote attacker to inject malicious scripts into web pages viewed by other users of the UniFi Network Application. If exploited, an attacker could hijack user sessions, steal credentials, or redirect users to malicious websites, thereby compromising the security and privacy of users accessing the UniFi Network Application interface. This XSS vulnerability affects versions prior to 7.4.156 of the UniFi Network Application.
Ubiquiti strongly recommends that all users of UniFi Network Application and UniFi Protect immediately update their software to the patched versions: UniFi Network Application 7.4.156 or later, and UniFi Protect 2.11.4 or later. The company has provided detailed instructions and download links for the updated software on its official support website. Proactive patching is essential to safeguard against these severe security threats and maintain the integrity of network and surveillance infrastructure.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.