A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery.
Affected Products:
UniFi Access Points
UniFi Switches
UniFi LTE Backup
UniFi Express (Only Mesh Mode, Router mode is not affected)
  
Mitigation:
Update UniFi Access Points to Version 6.6.55 or later.
Update UniFi Switches to Version 6.6.61 or later.
Update UniFi LTE Backup to Version 6.6.57 or later.
Update UniFi Express to Version 3.2.5 or later.
            Affected Products:
UniFi Access Points
UniFi Switches
UniFi LTE Backup
UniFi Express (Only Mesh Mode, Router mode is not affected)
Mitigation:
Update UniFi Access Points to Version 6.6.55 or later.
Update UniFi Switches to Version 6.6.61 or later.
Update UniFi LTE Backup to Version 6.6.57 or later.
Update UniFi Express to Version 3.2.5 or later.
Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Thu, 27 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Ubiquiti
         Ubiquiti unifi Uap Firmware  | 
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:o:ubiquiti:unifi_uap_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Ubiquiti
         Ubiquiti unifi Uap Firmware  | 
|
| Metrics | 
        
        ssvc
         
  | 
Thu, 15 Aug 2024 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-03-27T20:55:19.431Z
Reserved: 2024-01-05T01:04:06.642Z
Link: CVE-2024-22054
Updated: 2024-08-01T22:35:34.831Z
Status : Awaiting Analysis
Published: 2024-02-20T18:15:51.393
Modified: 2025-03-27T21:15:44.933
Link: CVE-2024-22054
No data.
                        OpenCVE Enrichment
                    No data.