First published: Tue Jul 30 2019(Updated: )
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Unifi Controller | <=5.10.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
The severity of CVE-2019-5456 is high with a CVSS score of 8.1.
UniFi Controller versions up to and including 5.10.21 are affected by CVE-2019-5456.
Update your UniFi Controller to a version higher than 5.10.21 to fix CVE-2019-5456.
Yes, you can find more information about CVE-2019-5456 in the following references: [link1], [link2], [link3].