Description
An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.
Reserved 2025-01-10 | Published 2025-02-01 | Updated 2025-02-01 | Assigner
hackeroneMEDIUM: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Product status
Default status
unaffected
4.1.13 before 4.1.13
affected
Default status
unaffected
4.1.13 before 4.1.13
affected
Default status
unaffected
4.1.13 before 4.1.13
affected
Default status
unaffected
4.1.13 before 4.1.13
affected
Default status
unaffected
4.1.13 before 4.1.13
affected
Default status
unaffected
4.1.11 before 4.1.11
affected
Default status
unaffected
4.1.11 before 4.1.11
affected
Default status
unaffected
4.1.11 before 4.1.11
affected
Default status
unaffected
4.1.11 before 4.1.11
affected
Default status
unaffected
4.1.11 before 4.1.11
affected
Default status
unaffected
4.1.13 before 4.1.13
affected
Default status
unaffected
4.1.13 before 4.1.13
affected
References
community.ui.com/...045/6011bc61-f2eb-457f-b71d-755703817aaf
cve.org (CVE-2025-23091)
nvd.nist.gov (CVE-2025-23091)
Download JSON
Subscribe to our newsletter to learn more about our work.