CVE-2023-28361: CSRF
A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28361?
CVE-2023-28361 is classified as a Cross-site WebSocket Hijacking vulnerability, which poses a significant risk to user confidentiality.
How do I fix CVE-2023-28361?
To fix CVE-2023-28361, upgrade UniFi OS to version 3.0.13 or later.
Which products are affected by CVE-2023-28361?
CVE-2023-28361 affects UniFi OS versions up to and including 2.5.
What can an attacker do with CVE-2023-28361?
An attacker can access confidential information by tricking a UniFi OS user into visiting a malicious webpage.
Is my UniFi device vulnerable to CVE-2023-28361?
If your device is running UniFi OS version 2.5 or earlier, it is vulnerable to CVE-2023-28361.