CVE-2019-25652: UniFi Network Controller Improper Certificate Validation Leading to Credential Theft via MITM
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and obtain credentials by exploiting the insecure SSL host verification mechanism in the SMTP certificate validation process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
UniFi Network Controllerto a version that resolves this vulnerability.Fixed in 5.10.22 - Upgrade
Upgrade
UniFi Network Controllerto a version that resolves this vulnerability.Fixed in 5.11.18
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25652?
CVE-2019-25652 has a high severity rating due to its ability to allow man-in-the-middle attacks resulting in potential credential theft.
How do I fix CVE-2019-25652?
To fix CVE-2019-25652, upgrade the Ubiquiti UniFi Network Controller to version 5.10.22 or above, or 5.11.18 or above.
What kind of vulnerability is CVE-2019-25652?
CVE-2019-25652 is an improper certificate validation vulnerability that can be exploited through man-in-the-middle attacks.
What are the affected versions for CVE-2019-25652?
CVE-2019-25652 affects Ubiquiti UniFi Network Controller versions prior to 5.10.22 and 5.11.x versions prior to 5.11.18.
Who is impacted by CVE-2019-25652?
Users of the Ubiquiti UniFi Network Controller who have not updated to the fixed versions are at risk of this vulnerability.