Ubiquiti UniFi Network Controller
cpe:2.3:a:ubnt:unifi_controller:*:*:*:*:*:*:*, +2 more
- < 5.10.22
- >= 5.11, < 5.11.18
A vulnerability exists in Ubiquiti UniFi Network Controller versions prior to 5.10.22 and 5.11.x prior to 5.11.18, due to improper certificate verification. This flaw allows adjacent network attackers to perform man-in-the-middle attacks by presenting a fraudulent SSL certificate during SMTP connections. Exploiting the inadequate SSL host verification in the SMTP certificate validation process, attackers can intercept SMTP traffic and capture credentials.
Exploitation of this vulnerability could lead to unauthorized interception of SMTP traffic and theft of credentials.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.