First published: Fri Apr 01 2022(Updated: )
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Ua Lite Firmware | <3.8.31.13 | |
Ui Ua Lite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22570 is a buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier).
A malicious actor who has gained access to a network can exploit CVE-2022-22570 to control all connected UA devices.
Yes, the vulnerability is fixed in Version 3.8.31.13 and later of the UniFi Door Access Reader Lite’s (UA Lite) firmware.
CVE-2022-22570 has a severity level of critical.
CVE-2022-22570 is associated with CWE-119 and CWE-120.