Security Advisory

CVE-2024-22054

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-02-20 17:14:34
Last updated 2025-03-27 20:55:19
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi Access Points to Version 6.6.55 or later. Update UniFi Switches to Version 6.6.61 or later. Update UniFi LTE Backup to Version 6.6.57 or later. Update UniFi Express to Version 3.2.5 or later.