Command injection in the process of downloading the latest version of the cloud key firmware through the unifi management software.
High
U
Ubiquiti Inc.
Submitted None
Team Summary
Official summary from Ubiquiti Inc.
In UniFi Cloud Key versions prior to `5.3.12`, `5.4.9` and `5.5.2`, the firmware is downloaded in a unprotected channel, with allow an attacker in an MitM scenario to interfere with the communication, and possibly modifying the firmware during an update. The versions `5.3.12`, `5.4.9` and `5.5.2` fix this problem by utilizing encrypted channel to download the firmware.
Actions:
Reported by
dblack
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Command Injection - Generic