UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.
2023-07-01T00:15:10.337
2024-11-26T19:15:20.320
Modified
CVSSv3.1: 9.0 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | ui | unifi_os | 3.1 | Yes |
| Hardware | ui | cloud_key_gen2 | - | No |
| Hardware | ui | cloud_key_gen2_plus | - | No |