
Cloud Vulnerability DB
A community-led vulnerabilities database
A backup file vulnerability was discovered in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems. The vulnerability was assigned CVE-2023-28365 and was published on June 30, 2023. This security flaw affects UniFi Network Application installations on Linux-based systems (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 9.1 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')) (NVD).
The vulnerability allows application administrators to execute malicious commands on the host device being restored during the backup restoration process. Given the CVSS scoring, this indicates potential for complete compromise of system confidentiality, integrity, and availability (NVD).
Users are advised to upgrade to UniFi Network Application version 7.4.156 or later, which contains fixes for this vulnerability (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."