Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-35085

Description

An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products:All UniFi Access Points (Version 6.5.50 and earlier)All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation:Update UniFi Access Points to Version 6.5.62 or later.Update the UniFi Switches to Version 6.5.59 or later.

POC

Reference

No PoCs from references.

Github

- https://github.com/maoruiQa/CVE-2023-35085-POC-EXP

- https://github.com/plzheheplztrying/cve_monitor