CVE Vulnerabilities

CVE-2024-45205

Improper Certificate Validation

Published: Dec 04, 2024 | Modified: Dec 04, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point.

Affected Products: UniFi iOS App (Version 10.17.7 and earlier)

Mitigation: UniFi iOS App (Version 10.18.0 or later).

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References