Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3119 | An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 | |
| Metrics |
ssvc
|
Sat, 01 Feb 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update. | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-03-13T12:54:46.381Z
Reserved: 2025-01-10T19:05:52.772Z
Link: CVE-2025-23091
Updated: 2025-02-12T20:41:13.170Z
Status : Deferred
Published: 2025-02-01T07:15:08.277
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-23091
No data.
OpenCVE Enrichment
No data.
EUVD