CVE-2024-27981
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device.
Affected Products:
UniFi Network Application (Version 8.0.28 and earlier) .
Mitigation:
Update UniFi Network Application to Version 8.1.113 or later.
Una vulnerabilidad de inyección de comandos encontrada en servidores de red UniFi autohospedados (Linux) con la aplicación de red UniFi (versión 8.0.28 y anteriores) permite a un actor malicioso con credenciales de administrador de la aplicación de red UniFi escalar privilegios a root en el dispositivo host. Productos afectados: Aplicación de red UniFi (Versión 8.0.28 y anteriores). Mitigación: actualice la aplicación UniFi Network a la versión 8.1.113 o posterior.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-02-29 CVE Reserved
- 2024-04-04 CVE Published
- 2024-04-05 EPSS Updated
- 2024-09-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://community.ui.com/releases/Security-Advisory-Bulletin-038-038/9d13fead-47de-4372-b2c1-745b8d6b0399 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ubiquiti Inc Search vendor "Ubiquiti Inc" | UniFi Network Application Search vendor "Ubiquiti Inc" for product "UniFi Network Application" | 8.1.113 Search vendor "Ubiquiti Inc" for product "UniFi Network Application" and version "8.1.113" | en |
Affected
|