Impact
A malicious actor with access to the network and low privileges can exploit an improper access control flaw in the UniFi Access Application to elevate privileges on the host device. The vulnerability is rated with a CVSS score of 9.9, indicating a critical impact on confidentiality, integrity, and availability for affected systems.
Affected Systems
The vulnerability affects Ubiquiti Inc.’s UniFi Access Application. Specific affected versions are not listed in the available data.
Risk and Exploitability
The CVSS score of 9.9 categorizes this flaw as critical, and although the EPSS score is not available, the absence of a KEV listing suggests that it has not yet been widely exploited. The review indicates that a local network presence and low privileges are sufficient prerequisites, implying that an attacker could target any device on the same network segment. Given its severity and the potential for local privilege escalation, the risk remains high until a patch is applied.
OpenCVE Enrichment