CVE-2023-31997: Critical severity unifi os vulnerability
Published Jun 30, 2023
·Updated
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.
Affected Software
6 affected components
UI Unifi Os=3.1
UI Cloud Key Gen2
UI Cloud Key Gen2 Plus
All of the following
UI Unifi Os=3.1
Any of the following
UI Cloud Key Gen2
UI Cloud Key Gen2 Plus
Event History
Jun 30, 2023
CVE Published
via MITRE·11:39 PM
Data Sourced
via MITRE·11:39 PM
Description
Jul 1, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-31997.
2
What is the severity of CVE-2023-31997?
CVE-2023-31997 has a severity level of critical with a value of 9.
3
Which version of UniFi OS is affected by CVE-2023-31997?
UniFi OS version 3.1 is affected by CVE-2023-31997.
4
How can a user on a local network access MongoDB through this vulnerability?
UniFi OS 3.1 introduces a misconfiguration that allows users on a local network to access MongoDB.
5
Are all Cloud Keys vulnerable to CVE-2023-31997?
No, only Applicable Cloud Keys that are running UniFi OS 3.1 and hosting the UniFi Network application are vulnerable.