CVE Database
/

CVE-2023-31997

Back to search

CVE-2023-31997

Published: Jun 30, 2023

Modified: Nov 26, 2024

PUBLISHED

Description

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.

VendorProductVersions

Ubiquiti Inc.

UniFi OS

affected
3.1.13 - <= 3.1.13

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now