Full Report
Ubiquiti security advisory (AV26-954)
Analysis Summary
# Vulnerability: Authentication Bypass in UniFi Gateways and Cloud Gateways
## CVE Details
- **CVE ID:** CVE-2024-42030
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-288 (Authentication Bypass Using an Alternate Path)
## Affected Systems
- **Products:** Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, UniFi Express, UniFi Gateways.
- **Versions:**
- Cloud Gateways / Dream Series / Enterprise Firewalls / Express 7: Prior to v5.1.31
- UniFi Express: Prior to v4.0.21
- UniFi Gateways (UXG Series): Prior to v5.1.26
- **Configurations:** Systems with the UniFi Network application exposed to the network, specifically when configured with certain identity management or remote access features.
## Vulnerability Description
A vulnerability exists in the authentication logic of affected UniFi Gateway and Cloud Gateway devices. An unauthenticated attacker can exploit a flaw in how the system processes specific requests to bypass authentication requirements. This allows the attacker to gain unauthorized administrative access to the UniFi Network application, effectively granting full control over the network management interface.
## Exploitation
- **Status:** Not currently reported as exploited in the wild (based on initial advisory release).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to network configurations, client lists, and logs)
- **Integrity:** High (Ability to modify firewall rules, VPN settings, and network configurations)
- **Availability:** High (Ability to disable network interfaces or factory reset devices)
## Remediation
### Patches
Ubiquiti has released the following firmware/application updates to address this vulnerability:
- **UniFi OS / Network Application:** Update to version **5.1.31** or later for Dream/Cloud/Enterprise series.
- **UniFi Express:** Update to version **4.0.21** or later.
- **UniFi Gateways (UXG):** Update to version **5.1.26** or later.
### Workarounds
- **Network Isolation:** Ensure the management interface (UniFi Network application) is not exposed to the public internet.
- **Access Control Lists (ACLs):** Restrict access to the management IP addresses to known, trusted administrative subnets only.
## Detection
- **Indicators of Compromise:** Monitor audit logs for unusual administrative logins from unexpected IP addresses or at irregular times. Check for the creation of unauthorized administrator accounts.
- **Detection Methods:** Review system logs for anomalies in authentication requests directed at the management portal.
## References
- **Vendor Advisory:** hxxps[://]community[.]ui[.]com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/ubiquiti-security-advisory-av26-954