ZDI-CAN-23187: ZDI-24-880: (Pwn2Own) Ubiquiti Networks EV Station EVCLauncher Improper Certificate Validation Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Ubiquiti Networks EV Station. User interaction is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2024-29207.
Affected Software
1 affected component
Ubiquiti Networks EV Station
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23187?
The severity of ZDI-CAN-23187 is rated at 6.3 on the CVSS scale.
2
How do I fix ZDI-CAN-23187?
To fix ZDI-CAN-23187, ensure that you update to the latest version of Ubiquiti Networks EV Station.
3
What type of attacks does ZDI-CAN-23187 allow?
ZDI-CAN-23187 allows network-adjacent attackers to compromise the integrity of downloaded information.
4
Is user interaction required to exploit ZDI-CAN-23187?
User interaction is not required to exploit ZDI-CAN-23187.
5
Which software is affected by ZDI-CAN-23187?
ZDI-CAN-23187 affects Ubiquiti Networks EV Station.