CVE-2014-2227: Medium severity ubiquiti unifi video controller vulnerability
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2227?
CVE-2014-2227 is classified as a medium severity vulnerability due to its impact on the Same Origin Policy.
How do I fix CVE-2014-2227?
To mitigate CVE-2014-2227, upgrade Ubiquiti Networks UniFi Video to version 3.0.1 or later.
What type of attack does CVE-2014-2227 allow?
CVE-2014-2227 allows remote attackers to bypass the Same Origin Policy using a crafted SWF file.
Which versions of Ubiquiti Networks UniFi Video are affected by CVE-2014-2227?
CVE-2014-2227 affects Ubiquiti Networks UniFi Video versions prior to 3.0.1, specifically up to version 2.1.3.
What is the primary cause of CVE-2014-2227?
The primary cause of CVE-2014-2227 is the default cross-domain policy (crossdomain.xml) that does not restrict application access.