CVE-2023-23119
Published on: Not Yet Published
Last Modified on: 02/10/2023 04:03:00 PM UTC
Certain versions of Af-2x from Ui contain the following vulnerability:
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X Radio firmware version 3.2.2 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
- CVE-2023-23119 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.9 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Weak Firmware Integrity Check Vulnerability During Firmware Update in Ubiquiti airFiber AF2X Radio - HackMD | hackmd.io text/html |
![]() |
No Description Provided | community.ui.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airF…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Ui | Af-2x | - | All | All | All |
Operating System | Ui | Af-2x Firmware | All | All | All | All |
- cpe:2.3:h:ui:af-2x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ui:af-2x_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-23119 : The use of the cyclic redundancy check CRC algorithm for integrity check during firmware update… twitter.com/i/web/status/1… | 2023-02-02 17:05:55 |
![]() |
CVE-2023-23119 | 2023-02-02 17:38:49 |