A vulnerability has been discovered in Ubiquiti UniFi, which can lead to local privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Ubiquiti UniFi: Privilege Escalation Date: November 06, 2024 Bugs: #941922 ID: 202411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Ubiquiti UniFi, which can lead to local privilege escalation. Background ========== Ubiquiti UniFi is a Management Controller for Ubiquiti Networks UniFi APs. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------ ------------ net-wireless/unifi < 8.5.6 > = 8.5.6 Description =========== A vulnerability has been discovered in Ubiquiti UniFi. Please review the CVE identifier referenced below for details. Impact ====== The vulnerability allows a malicious actor with a local operational system user to execute high privilege actions on UniFi Network Server. Workaround ========== There is no known workaround at this time. Resolution ========== All Ubiquiti UniFi users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/unifi-8.5.6" References ========== [ 1 ] CVE-2024-42028 https://nvd.nist.gov/vuln/detail/CVE-2024-42028 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202411-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any securityconcerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.