Skip to main content

Vendor/product archive

ui / unifi_controller CVEs

Beta · best-effort

6 CVEs tagged to ui / unifi_controller0 Critical, 4 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2020-12695

Published Jun 8, 2020

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment t…

CVSS 7.5 · High
evidence mentions
4
Buzz score
24.1

CVE-2019-5456

Published Jul 30, 2019

SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2226

Published Jul 29, 2014

Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspe…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3572

Published Dec 31, 2013

Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitra…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1