CVE-2023-23912
Ubiquiti Networks EdgeOS dhcp6c Command Injection Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Ubiquiti Networks EdgeOS. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the dhcp6c daemon. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-19 CVE Reserved
- 2023-02-09 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-10-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-75: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://community.ui.com/releases/Security-Advisory-Bulletin-028-028/696e4e3b-718c-4da4-9a21-965a85633b5f | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ui Search vendor "Ui" | Usg Firmware Search vendor "Ui" for product "Usg Firmware" | < 4.4.57 Search vendor "Ui" for product "Usg Firmware" and version " < 4.4.57" | - |
Affected
| in | Ui Search vendor "Ui" | Usg Search vendor "Ui" for product "Usg" | - | - |
Safe
|
Ui Search vendor "Ui" | Usg-pro-4 Firmware Search vendor "Ui" for product "Usg-pro-4 Firmware" | < 4.4.57 Search vendor "Ui" for product "Usg-pro-4 Firmware" and version " < 4.4.57" | - |
Affected
| in | Ui Search vendor "Ui" | Usg-pro-4 Search vendor "Ui" for product "Usg-pro-4" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-10x Firmware Search vendor "Ui" for product "Er-10x Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-10x Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-10x Search vendor "Ui" for product "Er-10x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-10x Firmware Search vendor "Ui" for product "Er-10x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-10x Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-10x Search vendor "Ui" for product "Er-10x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-10x Firmware Search vendor "Ui" for product "Er-10x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-10x Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-10x Search vendor "Ui" for product "Er-10x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-10x Firmware Search vendor "Ui" for product "Er-10x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-10x Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-10x Search vendor "Ui" for product "Er-10x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-10x Firmware Search vendor "Ui" for product "Er-10x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-10x Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-10x Search vendor "Ui" for product "Er-10x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12 Firmware Search vendor "Ui" for product "Er-12 Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-12 Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-12 Search vendor "Ui" for product "Er-12" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12 Firmware Search vendor "Ui" for product "Er-12 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12 Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-12 Search vendor "Ui" for product "Er-12" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12 Firmware Search vendor "Ui" for product "Er-12 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12 Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-12 Search vendor "Ui" for product "Er-12" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12 Firmware Search vendor "Ui" for product "Er-12 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12 Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-12 Search vendor "Ui" for product "Er-12" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12 Firmware Search vendor "Ui" for product "Er-12 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12 Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-12 Search vendor "Ui" for product "Er-12" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12p Firmware Search vendor "Ui" for product "Er-12p Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-12p Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-12p Search vendor "Ui" for product "Er-12p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12p Firmware Search vendor "Ui" for product "Er-12p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12p Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-12p Search vendor "Ui" for product "Er-12p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12p Firmware Search vendor "Ui" for product "Er-12p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12p Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-12p Search vendor "Ui" for product "Er-12p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12p Firmware Search vendor "Ui" for product "Er-12p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12p Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-12p Search vendor "Ui" for product "Er-12p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-12p Firmware Search vendor "Ui" for product "Er-12p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-12p Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-12p Search vendor "Ui" for product "Er-12p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-4 Firmware Search vendor "Ui" for product "Er-4 Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-4 Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-4 Search vendor "Ui" for product "Er-4" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-4 Firmware Search vendor "Ui" for product "Er-4 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-4 Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-4 Search vendor "Ui" for product "Er-4" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-4 Firmware Search vendor "Ui" for product "Er-4 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-4 Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-4 Search vendor "Ui" for product "Er-4" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-4 Firmware Search vendor "Ui" for product "Er-4 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-4 Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-4 Search vendor "Ui" for product "Er-4" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-4 Firmware Search vendor "Ui" for product "Er-4 Firmware" | 2.0.9 Search vendor "Ui" for product "Er-4 Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-4 Search vendor "Ui" for product "Er-4" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-6p Firmware Search vendor "Ui" for product "Er-6p Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-6p Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-6p Search vendor "Ui" for product "Er-6p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-6p Firmware Search vendor "Ui" for product "Er-6p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-6p Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-6p Search vendor "Ui" for product "Er-6p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-6p Firmware Search vendor "Ui" for product "Er-6p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-6p Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-6p Search vendor "Ui" for product "Er-6p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-6p Firmware Search vendor "Ui" for product "Er-6p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-6p Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-6p Search vendor "Ui" for product "Er-6p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-6p Firmware Search vendor "Ui" for product "Er-6p Firmware" | 2.0.9 Search vendor "Ui" for product "Er-6p Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-6p Search vendor "Ui" for product "Er-6p" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-8-xg Firmware Search vendor "Ui" for product "Er-8-xg Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-8-xg Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-8-xg Search vendor "Ui" for product "Er-8-xg" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-8-xg Firmware Search vendor "Ui" for product "Er-8-xg Firmware" | 2.0.9 Search vendor "Ui" for product "Er-8-xg Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-8-xg Search vendor "Ui" for product "Er-8-xg" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-8-xg Firmware Search vendor "Ui" for product "Er-8-xg Firmware" | 2.0.9 Search vendor "Ui" for product "Er-8-xg Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-8-xg Search vendor "Ui" for product "Er-8-xg" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-8-xg Firmware Search vendor "Ui" for product "Er-8-xg Firmware" | 2.0.9 Search vendor "Ui" for product "Er-8-xg Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-8-xg Search vendor "Ui" for product "Er-8-xg" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-8-xg Firmware Search vendor "Ui" for product "Er-8-xg Firmware" | 2.0.9 Search vendor "Ui" for product "Er-8-xg Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-8-xg Search vendor "Ui" for product "Er-8-xg" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x Firmware Search vendor "Ui" for product "Er-x Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-x Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-x Search vendor "Ui" for product "Er-x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x Firmware Search vendor "Ui" for product "Er-x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-x Search vendor "Ui" for product "Er-x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x Firmware Search vendor "Ui" for product "Er-x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-x Search vendor "Ui" for product "Er-x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x Firmware Search vendor "Ui" for product "Er-x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-x Search vendor "Ui" for product "Er-x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x Firmware Search vendor "Ui" for product "Er-x Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-x Search vendor "Ui" for product "Er-x" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x-sfp Firmware Search vendor "Ui" for product "Er-x-sfp Firmware" | < 2.0.9 Search vendor "Ui" for product "Er-x-sfp Firmware" and version " < 2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-x-sfp Search vendor "Ui" for product "Er-x-sfp" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x-sfp Firmware Search vendor "Ui" for product "Er-x-sfp Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x-sfp Firmware" and version "2.0.9" | - |
Affected
| in | Ui Search vendor "Ui" | Er-x-sfp Search vendor "Ui" for product "Er-x-sfp" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x-sfp Firmware Search vendor "Ui" for product "Er-x-sfp Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x-sfp Firmware" and version "2.0.9" | hotfix2 |
Affected
| in | Ui Search vendor "Ui" | Er-x-sfp Search vendor "Ui" for product "Er-x-sfp" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x-sfp Firmware Search vendor "Ui" for product "Er-x-sfp Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x-sfp Firmware" and version "2.0.9" | hotfix4 |
Affected
| in | Ui Search vendor "Ui" | Er-x-sfp Search vendor "Ui" for product "Er-x-sfp" | - | - |
Safe
|
Ui Search vendor "Ui" | Er-x-sfp Firmware Search vendor "Ui" for product "Er-x-sfp Firmware" | 2.0.9 Search vendor "Ui" for product "Er-x-sfp Firmware" and version "2.0.9" | hotfix5 |
Affected
| in | Ui Search vendor "Ui" | Er-x-sfp Search vendor "Ui" for product "Er-x-sfp" | - | - |
Safe
|