First published: Fri Dec 23 2022(Updated: )
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Airfiber Gigabeam Firmware | <1.4.1 | |
Ui Airfiber Gigabeam | ||
Ui Airfiber 60-xg Firmware | <1.0.0 | |
Ui Airfiber 60-xg | ||
Ui Airfiber 60-hd Firmware | <1.0.0 | |
Ui Airfiber 60-hd | ||
Ui Airfiber 60-lr Firmware | <2.6.2 | |
Ui Airfiber 60-lr | ||
Ui Airmax Ac Firmware | <8.7.11 | |
Ui Airmax Ac | ||
Ui Airfiber 60 Firmware | <2.6.2 | |
Ui Airfiber 60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44565 is an improper access validation vulnerability that exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1.
A malicious actor can exploit CVE-2022-44565 to retrieve status and usage data from the UISP device.
CVE-2022-44565 has a severity rating of 5.3 (Medium).
CVE-2022-44565 affects airMAX AC versions earlier than 8.7.11, airFiber 60/LR versions earlier than 2.6.2, airFiber 60 XG/HD versions earlier than 1.0.0, and airFiber GBE versions earlier than 1.4.1.
Yes, updating to airMAX AC version 8.7.11, airFiber 60/LR version 2.6.2, airFiber 60 XG/HD version 1.0.0, or airFiber GBE version 1.4.1 will fix CVE-2022-44565.