« Volver al listado

CVE-2025-23091

Estado: AplazadaMedia (5.9)—

An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-23091",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-23091",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-03T15:47:37.586798Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "support@hackerone.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "Ubiquiti Inc",
          "product": "UDM",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.13",
              "lessThan": "4.1.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UDM-Pro",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.13",
              "lessThan": "4.1.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UDM-SE",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.13",
              "lessThan": "4.1.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UDM-Pro-Max",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.13",
              "lessThan": "4.1.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UDW",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.13",
              "lessThan": "4.1.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UNVR",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.11",
              "lessThan": "4.1.11",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UNVR PRO",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.11",
              "lessThan": "4.1.11",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UCKP",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.11",
              "lessThan": "4.1.11",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UCK",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.11",
              "lessThan": "4.1.11",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UCK-Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.11",
              "lessThan": "4.1.11",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "UCG-Max",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.13",
              "lessThan": "4.1.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ubiquiti Inc",
          "product": "EFG",
          "versions": [
            {
              "status": "affected",
              "version": "4.1.13",
              "lessThan": "4.1.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-02-01T07:15:08.277",
  "references": [
    {
      "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-045-045/6011bc61-f2eb-457f-b71d-755703817aaf",
      "source": "support@hackerone.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update."
    },
    {
      "lang": "es",
      "value": "Una validación de certificado incorrecta en dispositivos UniFi OS, con Identity Enterprise configurado, podría permitir que un actor malintencionado ejecute un ataque de intermediario (MitM) durante la actualización de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T08:51:54.640",
  "sourceIdentifier": "support@hackerone.com"
}