CVE-2019-5456: High severity ubiquiti unifi controller vulnerability
Published Jul 30, 2019
·Updated
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
Affected Software
1 affected component
UI UniFi Controller<=5.10.21
Event History
Jul 30, 2019
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Frequently Asked Questions
1
What is SMTP MITM?
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
2
What is the severity of CVE-2019-5456?
The severity of CVE-2019-5456 is high with a CVSS score of 8.1.
3
Which software versions are affected by CVE-2019-5456?
UniFi Controller versions up to and including 5.10.21 are affected by CVE-2019-5456.
4
How can I fix CVE-2019-5456?
Update your UniFi Controller to a version higher than 5.10.21 to fix CVE-2019-5456.
5
Is there any additional information available for CVE-2019-5456?
Yes, you can find more information about CVE-2019-5456 in the following references: [link1], [link2], [link3].