A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability
Published Feb 9, 2023
8.8
HIGHCVSS 3.1
EPSS 0.96%
Description
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.
Affected products
- Vendor n/a Product Ubiquiti EdgeRouter(s) and USG(s) Defaultn/a
- Version EdgeRouter(s) Version 2.0.9-hotfix.6 or later and USG(s) to Version 4.4.57 or laterStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ubiquiti EdgeRouter(s) and USG(s) | n/a |
|
Configuration 1
- < 4.4.57
Configuration 2
- < 4.4.57
Configuration 3
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
Configuration 4
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
Configuration 5
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
Configuration 6
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
Configuration 7
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
Configuration 8
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
Configuration 9
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
Configuration 10
- < 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
- 2.0.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://community.ui.com/releases/Security-Advisory-Bulletin-028-028/696e4e3b-718c-4da4-9a21-965a85633b5f ExploitPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-27995 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://community.ui.com/releases/Security-Advisory-Bulletin-028-028/696e4e3b-718c-4da4-9a21-965a85633b5f | ExploitPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-27995 | Advisory |
Change history (0)
No recorded changes yet.