CVE-2019-25651: Ubiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device Control
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow attackers to recover encryption keys from captured traffic. Attackers with adjacent network access can capture sufficient encrypted traffic and exploit AES-CBC mode vulnerabilities to derive the encryption keys, enabling unauthorized control and management of network devices.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ubiquiti UniFi Network Controllerto a version that resolves this vulnerability.Fixed in 5.10.12 - Upgrade
Upgrade
UAP FWto a version that resolves this vulnerability.Fixed in 4.0.6 - Upgrade
Upgrade
UAP-AC Outdoor FWto a version that resolves this vulnerability.Fixed in 3.8.17 - Upgrade
Upgrade
USW FWto a version that resolves this vulnerability.Fixed in 4.0.6 - Upgrade
Upgrade
USG FWto a version that resolves this vulnerability.Fixed in 4.4.34
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25651?
CVE-2019-25651 has been assigned a medium severity rating due to its potential for unauthorized device control and key recovery.
How do I fix CVE-2019-25651?
To fix CVE-2019-25651, upgrade the Ubiquiti UniFi Network Controller to version 5.10.12 or later, and ensure all relevant firmware versions are updated.
Which Ubiquiti devices are affected by CVE-2019-25651?
CVE-2019-25651 affects Ubiquiti UniFi Network Controller prior to 5.10.12, and various firmware versions of UAP, UAP-AC, USW, and USG devices.
Can CVE-2019-25651 be exploited remotely?
Yes, CVE-2019-25651 can potentially be exploited remotely, allowing attackers to gain unauthorized access to affected devices.
Is there a workaround for CVE-2019-25651?
No official workaround has been recommended for CVE-2019-25651, so upgrading to the latest firmware is the best course of action.