Blog
Critical Ubiquiti UniFi Vulnerabilities: Is Your Network at Risk?
Christopher Souza | CEO
Ubiquiti has released security updates addressing 22 newly disclosed vulnerabilities affecting products and applications across its UniFi ecosystem. Of the 22 vulnerabilities, 21 received a Critical severity rating, including three with the maximum CVSS score of 10.0. The vulnerabilities affect technology that many organizations rely on for networking, security, communications, access control, and video surveillance.
Since these vulnerabilities are being actively exploited, organizations using Ubiquiti technology should identify affected systems and apply the appropriate security updates as soon as possible.
What Products Are Affected?
According to Ubiquiti’s Security Advisory Bulletin, the vulnerabilities span numerous UniFi applications and devices. This includes UniFi OS, Network, Protect, Talk, Access, Connect, Cloud Keys, gateways, Dream Machines, network video recorders, network attached storage devices, and other UniFi hardware and applications.
The widespread nature of the advisory is particularly important for businesses that use multiple UniFi products throughout their environment. An organization may have affected technology supporting several different functions, making it important to review the entire UniFi environment rather than focusing on a single device.
What Could These Vulnerabilities Allow an Attacker to Do?
The vulnerabilities differ depending on the affected product, but several could give an attacker significant access to a vulnerable system. Potential consequences identified in Ubiquiti’s advisory include:
- Bypassing authentication controls
- Executing unauthorized commands
- Escalating user privileges
- Making unauthorized system changes
- Gaining elevated access to affected devices or applications
What Should Organizations Do Now?
Organizations using UniFi technology should review their environments to determine which affected products and versions are currently in use. Ubiquiti has released specific updated versions for the affected products in its advisory, and vulnerable systems should be brought to the appropriate vendor-recommended version as soon as possible.
Organizations should also verify that UniFi management interfaces are appropriately restricted and are not unnecessarily accessible from untrusted networks.
Because UniFi products may support critical network, security, phone, access control, or surveillance functions, updating them can temporarily interrupt connectivity or other business services. Updates should therefore be scheduled promptly while accounting for the operational impact of taking affected equipment or applications offline.
Contact TSI Today!
With critical vulnerabilities affecting such a broad range of UniFi technology, organizations should not delay reviewing and updating affected systems.
If your organization uses Ubiquiti UniFi products, TSI can help identify affected technology, assess your environment, and coordinate the necessary updates while minimizing disruption to your operations.
Contact TSI today to make sure your environment is properly protected. Fail to prepare, prepare to fail!
About Technical Support International
TSI is 37-year old cybersecurity (MSSP) and IT support (MSP) company specializing in helping DIB organizations address their NIST 800-171 and CMMC compliance obligations. As a CMMC-AB Registered Provider Organization (RPO), TSI offers a complete NIST 800-171 and CMMC support solution to help guide our clients toward a successful certification audit and provide the assurance that they’re adhering to these expansive compliance requirements.
Categories
- Backup & Disaster Recovery
- Business Operations
- Case Studies
- Cloud Services
- Cyber Security
- Employee Spotlight
- Finance & Budgeting
- Glossary Term
- Governance & IT Compliance
- Managed Services
- Mobile Device Management
- Network Infrastructure
- NIST 800-171 & CMMC 2.0
- PCI
- Podcast
- Project Management
- TSI
- Uncategorized
- vCIO
Cyber Security Policy Starter Kit:
10 Critical Policies That Every Company Should Have in Place
