Affected Products:
UniFi iOS App (Version 10.17.7 and earlier)
Mitigation:
UniFi iOS App (Version 10.18.0 or later).
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41709 | An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App (Version 10.17.7 and earlier) Mitigation: UniFi iOS App (Version 10.18.0 or later). |
Wed, 04 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ui
Ui unifi |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:ui:unifi:*:*:*:*:*:ios:*:* | |
| Vendors & Products |
Ui
Ui unifi |
|
| Metrics |
ssvc
|
Wed, 04 Dec 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App (Version 10.17.7 and earlier) Mitigation: UniFi iOS App (Version 10.18.0 or later). | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-12-04T16:29:27.075Z
Reserved: 2024-08-23T01:00:01.061Z
Link: CVE-2024-45205
Updated: 2024-12-04T16:29:19.186Z
Status : Deferred
Published: 2024-12-04T02:15:05.323
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-45205
No data.
OpenCVE Enrichment
No data.
EUVD