A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery.
Affected Products:
UniFi Access Points
UniFi Switches
UniFi LTE Backup
UniFi Express (Only Mesh Mode, Router mode is not affected)
Mitigation:
Update UniFi Access Points to Version 6.6.55 or later.
Update UniFi Switches to Version 6.6.61 or later.
Update UniFi LTE Backup to Version 6.6.57 or later.
Update UniFi Express to Version 3.2.5 or later.
References
Configurations
No configuration.
History
27 Mar 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 |
Information
Published : 2024-02-20 18:15
Updated : 2025-03-27 21:15
NVD link : CVE-2024-22054
Mitre link : CVE-2024-22054
CVE.ORG link : CVE-2024-22054
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation