Home

Description

An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.

PUBLISHED Reserved 2025-01-10 | Published 2025-02-01 | Updated 2025-03-13 | Assigner hackerone




MEDIUM: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Product status

Default status
unaffected

4.1.13 (semver) before 4.1.13
affected

Default status
unaffected

4.1.13 (semver) before 4.1.13
affected

Default status
unaffected

4.1.13 (semver) before 4.1.13
affected

Default status
unaffected

4.1.13 (semver) before 4.1.13
affected

Default status
unaffected

4.1.13 (semver) before 4.1.13
affected

Default status
unaffected

4.1.11 (semver) before 4.1.11
affected

Default status
unaffected

4.1.11 (semver) before 4.1.11
affected

Default status
unaffected

4.1.11 (semver) before 4.1.11
affected

Default status
unaffected

4.1.11 (semver) before 4.1.11
affected

Default status
unaffected

4.1.11 (semver) before 4.1.11
affected

Default status
unaffected

4.1.13 (semver) before 4.1.13
affected

Default status
unaffected

4.1.13 (semver) before 4.1.13
affected

References

community.ui.com/...045/6011bc61-f2eb-457f-b71d-755703817aaf

cve.org (CVE-2025-23091)

nvd.nist.gov (CVE-2025-23091)

Download JSON