Full Report
Ubiquiti security advisory (AV26-850)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Ubiquiti UniFi Ecosystem (Bulletin 067)
## CVE Details
*Note: The provided source lists a collection of affected products under a single advisory (AV26-850/Bulletin 067). Specific individual CVE identifiers were not detailed in the summary text; however, based on the "Critical" classification by the Cyber Centre:*
- **CVE ID:** CVE-2024-XXXXX (Multiple)
- **CVSS Score:** Critical (Estimated 9.0 - 10.0 range based on advisory severity)
- **CWE:** Not specified (Likely includes Improper Authentication or Injection based on product spread)
## Affected Systems
- **Products:**
- UniFi OS Server
- UniFi Connect Application
- UniFi Network Application
- UID Enterprise Agent
- UniFi Access Application
- UniFi Protect Application
- UniFi Connect Display Cast Pro
- UniFi Enterprise Audio/Video Bridge
- UniFi Talk Application
- UniFi Protect AI Key
- **Versions:**
- UniFi OS Server: ≤ 5.1.21
- UniFi Connect Application: ≤ 3.24.20
- UniFi Network Application: ≤ 10.4.57
- UID Enterprise Agent: ≤ 1.61.8
- UniFi Access Application: ≤ 4.3.3
- UniFi Protect Application: ≤ 7.1.87
- UniFi Connect Display Cast Pro: ≤ 1.0.108
- UniFi Enterprise Audio/Video Bridge: ≤ 1.0.10
- UniFi Talk Application: ≤ 5.2.7
- UniFi Protect AI Key: ≤ 2.1.3
- **Configurations:** Systems running affected application versions across UniFi Console hardware and self-hosted environments.
## Vulnerability Description
While specific technical details for each application were not explicitly itemized in the briefing, the advisory indicates critical flaws across the management stack (Network, Talk, Access, Protect). These flaws typically involve unauthorized access to system configurations or remote code execution risks within the UniFi OS environment.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild; however, the advisory urges immediate patching.
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential access to surveillance feeds, network topology, and user data)
- **Integrity:** High (Potential to modify network configurations or access control rules)
- **Availability:** High (Potential for system disruption or denial of service)
## Remediation
### Patches
Ubiquiti recommends updating to versions higher than those listed above. Recommended versions include:
- **UniFi OS Server:** > 5.1.21
- **UniFi Network Application:** > 10.4.57
- **UniFi Protect Application:** > 7.1.87
- *(Check official UI release channels for the latest stable build for each specific hardware target)*
### Workarounds
- Isolate management interfaces from the public internet.
- Implement strict Firewall/ACLs to restrict access to UniFi OS ports (e.g., 8443, 443) to trusted IP addresses only.
- Disable remote access features if not strictly required.
## Detection
- **Indicators of Compromise:** Unusual administrative login activity, unauthorized changes to network settings, or unexpected outbound traffic from UniFi controllers.
- **Detection methods:** Audit system logs within the UniFi OS Settings -> System Log section for unrecognized SSH access or credential changes.
## References
- **Vendor Advisory:** hxxps[://]community[.]ui[.]com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9
- **Cyber Centre Alert:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/ubiquiti-security-advisory-av26-850