Unifi Controller

Vendor:

First CVE: Dec 31, 2013 · Active for 12 years

6
Total CVEs
More Total CVEs than 80% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Unifi Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2013
12 years ago
Most Recent CVE
Oct 27, 2020
2,096 days ago

CVE Severity & Scoring

Unifi Controller6 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network5 (83.3%)
Unknown1 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High2 (33.3%)
Unknown1 (16.7%)
User Interaction
None3 (50.0%)
Unknown1 (16.7%)
Required2 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (83.3%)
Unknown1 (16.7%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators
Feb 8, 20208.831NOYES
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment th
Jun 8, 20207.528NONO
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials
Jul 30, 20198.126NONO
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point ret
Oct 27, 20207.519NONO
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrar
Dec 31, 20136.117NONO
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspec
Jul 29, 20142.612NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Unifi Controller

Top CWEs

Versions

No cataloged versions.