An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
References
Link | Resource |
---|---|
https://community.ui.com/releases/Security-Advisory-Bulletin-027-027/123e4577-9f00-4777-abe1-64a1d56fee05 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Information
Published : 2022-12-23 07:15
Updated : 2023-01-04 10:15
NVD link : CVE-2022-44565
Mitre link : CVE-2022-44565
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
ui
- airfiber_60_firmware
- airfiber_60-hd_firmware
- airfiber_60-hd
- airfiber_60-lr
- airfiber_60-xg
- airfiber_gigabeam_firmware
- airfiber_gigabeam
- airmax_ac
- airfiber_60-xg_firmware
- airmax_ac_firmware
- airfiber_60-lr_firmware
- airfiber_60