CVE-2014-2226: Low severity ubiquiti unifi controller vulnerability
Published Jul 29, 2014
·Updated
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
UI UniFi Controller<=2.4.6
Event History
Jul 29, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2226?
CVE-2014-2226 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2014-2226?
To fix CVE-2014-2226, upgrade Ubiquiti UniFi Controller to version 3.2.1 or later.
3
What impact does CVE-2014-2226 have on my system?
CVE-2014-2226 allows man-in-the-middle attackers to obtain the administrative password hash, compromising system security.
4
Which versions of Ubiquiti UniFi Controller are affected by CVE-2014-2226?
CVE-2014-2226 affects Ubiquiti UniFi Controller versions prior to 3.2.1, including all versions up to 2.4.6.
5
Can CVE-2014-2226 be exploited remotely?
Yes, CVE-2014-2226 can be exploited remotely by attackers intercepting logs transmitted over a network.