Ubiquiti UniFi Access Management API Authentication Bypass Vulnerability
Vulnerability
A vulnerability exists in the Ubiquiti UniFi Access application, specifically in versions 3.3.22 through 3.4.31. A misconfiguration has exposed a management API on the door access application, allowing unauthorized access to the API by malicious actors on the management network. This vulnerability could be exploited to manipulate access control features or disrupt service.
Impact
Exploitation of this vulnerability could lead to unauthorized access to the management API, allowing for potential manipulation of access control features or disruption of service.
Remediation
Users are advised to update the UniFi Access application to version 4.0.21 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
