CVE Feed

    Dashboard / CVE / CVE-2023-35085

    CVE-2023-35085

    An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update the UniFi Switches to Version 6.5.59 or later.

    Published:Aug 10, 2023
    Last Modified:Dec 4, 2024
    EPS:Aug 10, 2023
    EPSS Score:0.05402
    CVSS Score:9.8

    Affected Products

    Vendor
    Ui
    Product
    U6-enterprise
    Vendor
    Ui
    Product
    U6-enterprise-iw
    Vendor
    Ui
    Product
    U6-extender
    Vendor
    Ui
    Product
    U6-iw
    Vendor
    Ui
    Product
    U6-lite
    Vendor
    Ui
    Product
    U6-lr
    Vendor
    Ui
    Product
    U6-mesh
    Vendor
    Ui
    Product
    U6-pro
    Vendor
    Ui
    Product
    U6\+
    Vendor
    Ui
    Product
    Uap-ac-iw
    Vendor
    Ui
    Product
    Uap-ac-lite
    Vendor
    Ui
    Product
    Uap-ac-lr
    Vendor
    Ui
    Product
    Uap-ac-m
    Vendor
    Ui
    Product
    Uap-ac-m-pro
    Vendor
    Ui
    Product
    Uap-ac-pro
    Vendor
    Ui
    Product
    Ubb
    Vendor
    Ui
    Product
    Ubb-xg
    Vendor
    Ui
    Product
    Unifi Switch Firmware
    Vendor
    Ui
    Product
    Unifi Uap Firmware
    Vendor
    Ui
    Product
    Us-16-150w
    Vendor
    Ui
    Product
    Us-24-250w
    Vendor
    Ui
    Product
    Us-48-500w
    Vendor
    Ui
    Product
    Us-8-150w
    Vendor
    Ui
    Product
    Us-8-60w
    Vendor
    Ui
    Product
    Us-xg-6poe
    Vendor
    Ui
    Product
    Usw-16-poe
    Vendor
    Ui
    Product
    Usw-24
    Vendor
    Ui
    Product
    Usw-24-poe
    Vendor
    Ui
    Product
    Usw-48
    Vendor
    Ui
    Product
    Usw-48-poe
    Vendor
    Ui
    Product
    Usw-aggregation
    Vendor
    Ui
    Product
    Usw-enterprise-24-poe
    Vendor
    Ui
    Product
    Usw-enterprise-48-poe
    Vendor
    Ui
    Product
    Usw-enterprise-8-poe
    Vendor
    Ui
    Product
    Usw-enterprisexg-24
    Vendor
    Ui
    Product
    Usw-flex
    Vendor
    Ui
    Product
    Usw-flex-xg
    Vendor
    Ui
    Product
    Usw-industrial
    Vendor
    Ui
    Product
    Usw-lite-16-poe
    Vendor
    Ui
    Product
    Usw-lite-8-poe
    Vendor
    Ui
    Product
    Usw-mission-critical
    Vendor
    Ui
    Product
    Usw-pro-24
    Vendor
    Ui
    Product
    Usw-pro-24-poe
    Vendor
    Ui
    Product
    Usw-pro-48
    Vendor
    Ui
    Product
    Usw-pro-48-poe
    Vendor
    Ui
    Product
    Usw-pro-aggregation
    Vendor
    Ui
    Product
    Uwb-xg

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High