CVE-2016-7792: High severity Ubiquiti Networks Unifi Ap Ac Lite Firmware vulnerability
Published Jan 23, 2017
·Updated
Ubiquiti Networks UniFi 5.2.7 does not restrict access to the database, which allows remote attackers to modify the database by directly connecting to it.
Affected Software
4 affected components
Ubiquiti Networks Unifi Ap Ac Lite Firmware<=5.2.7
Ubiquiti Networks Unifi Ap Ac Lite
All of the following
Ubiquiti Networks Unifi Ap Ac Lite Firmware<=5.2.7
Ubiquiti Networks Unifi Ap Ac Lite
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7792?
CVE-2016-7792 is considered a high severity vulnerability due to the potential for remote attackers to gain unauthorized access to the database.
2
How do I fix CVE-2016-7792?
To fix CVE-2016-7792, upgrade Ubiquiti Networks UniFi to a version later than 5.2.7 where the access control issues have been resolved.
3
Who is affected by CVE-2016-7792?
CVE-2016-7792 affects Ubiquiti Networks UniFi version 5.2.7 and potentially earlier versions.
4
What does CVE-2016-7792 allow attackers to do?
CVE-2016-7792 allows remote attackers to modify the database by directly accessing it without proper restrictions.
5
Is CVE-2016-7792 exploitable remotely?
Yes, CVE-2016-7792 is exploitable remotely due to the improper access control in the affected software.