// For flags

CVE-2024-27981

 

Severity Score

"-"
*CVSS v-

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device.

Affected Products:
UniFi Network Application (Version 8.0.28 and earlier) .

Mitigation:
Update UniFi Network Application to Version 8.1.113 or later.

Una vulnerabilidad de inyección de comandos encontrada en servidores de red UniFi autohospedados (Linux) con la aplicación de red UniFi (versión 8.0.28 y anteriores) permite a un actor malicioso con credenciales de administrador de la aplicación de red UniFi escalar privilegios a root en el dispositivo host. Productos afectados: Aplicación de red UniFi (Versión 8.0.28 y anteriores). Mitigación: actualice la aplicación UniFi Network a la versión 8.1.113 o posterior.

*Credits: N/A
CVSS Scores
Attack Vector
-
Attack Complexity
-
Privileges Required
-
User Interaction
-
Scope
-
Confidentiality
-
Integrity
-
Availability
-
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-02-29 CVE Reserved
  • 2024-04-04 CVE Published
  • 2024-04-05 EPSS Updated
  • 2024-09-13 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ubiquiti Inc
Search vendor "Ubiquiti Inc"
UniFi Network Application
Search vendor "Ubiquiti Inc" for product "UniFi Network Application"
8.1.113
Search vendor "Ubiquiti Inc" for product "UniFi Network Application" and version "8.1.113"
en
Affected