Unifi Controller
Vendor:
First CVE: Dec 31, 2013 · Active for 12 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Unifi Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2013
12 years ago
Most Recent CVE
Oct 27, 2020
2,096 days ago
CVE Severity & Scoring
Unifi Controller6 CVEs
17%
17%
67%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network5 (83.3%)
Unknown1 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High2 (33.3%)
Unknown1 (16.7%)
User Interaction
None3 (50.0%)
Unknown1 (16.7%)
Required2 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (83.3%)
Unknown1 (16.7%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2225HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators | Feb 8, 2020 | 8.8 | 31 | NO | YES |
CVE-2020-12695HIGH The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment th | Jun 8, 2020 | 7.5 | 28 | NO | NO |
CVE-2019-5456HIGH SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials | Jul 30, 2019 | 8.1 | 26 | NO | NO |
CVE-2020-27888HIGH An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point ret | Oct 27, 2020 | 7.5 | 19 | NO | NO |
CVE-2013-3572MEDIUM Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrar | Dec 31, 2013 | 6.1 | 17 | NO | NO |
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspec | Jul 29, 2014 | 2.6 | 12 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Unifi Controller
Top CWEs
Versions
No cataloged versions.