Cross-site WebSocket Hijacking (CSWSH) Vulnerability in UniFi OS 2.5 and Earlier

Cross-site WebSocket Hijacking (CSWSH) Vulnerability in UniFi OS 2.5 and Earlier

CVE-2023-28361 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.

Learn more about our Web App Pen Testing.