ZDI-24-880: (Pwn2Own) Ubiquiti Networks EV Station EVCLauncher Improper Certificate Validation Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Ubiquiti Networks EV Station. User interaction is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2024-29207.
Affected Software
1 affected component
Ubiquiti Networks EV Station
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-880?
The severity of ZDI-24-880 is rated at 6.3 on the CVSS scale.
2
How do I fix ZDI-24-880?
To fix ZDI-24-880, you should apply the latest security update provided by Ubiquiti Networks for the EV Station.
3
Who is affected by ZDI-24-880?
ZDI-24-880 affects installations of Ubiquiti Networks EV Station.
4
Can ZDI-24-880 be exploited without user interaction?
Yes, ZDI-24-880 can be exploited by network-adjacent attackers without requiring user interaction.
5
What does ZDI-24-880 compromise?
ZDI-24-880 compromises the integrity of downloaded information on affected installations.