Unifi Controller
UI · 5 CVEs
CVE-2020-12695
HIGH
hostapd: UPnP SUBSCRIBE misbehavior in WPS AP
Jun 8, 2020
CVE-2014-2225
HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow rem…
Feb 8, 2020
CVE-2019-5456
HIGH
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 a…
Jul 30, 2019
CVE-2014-2226
LOW
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-th…
Jul 29, 2014
CVE-2013-3572
MEDIUM
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi…
Dec 31, 2013
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-12695 | hostapd: UPnP SUBSCRIBE misbehavior in WPS AP | HIGH | 15.19% | Jun 8, 2020 |
| CVE-2014-2225 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authenticati… | HIGH | 1.28% | Feb 8, 2020 |
| CVE-2019-5456 | SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record th… | HIGH | 1.29% | Jul 30, 2019 |
| CVE-2014-2226 | Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive i… | LOW | 1.45% | Jul 29, 2014 |
| CVE-2013-3572 | Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attacke… | MEDIUM | 1.65% | Dec 31, 2013 |
Showing 1 to 5 of 5 CVEs