U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-38034

Change History

Initial Analysis by NIST 8/17/2023 10:42:06 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:ui:unifi_switch_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.5.32
     OR
          cpe:2.3:h:ui:us-16-150w:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:us-24-250w:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:us-48-500w:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:us-8-150w:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:us-8-60w:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:us-xg-6poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-16-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-24:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-24-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-48:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-48-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-aggregation:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-enterprise-24-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-enterprise-48-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-enterprise-8-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-enterprisexg-24:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-flex:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-flex-xg:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-industrial:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-lite-16-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-lite-8-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-mission-critical:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-pro-24:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-pro-24-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-pro-48:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-pro-48-poe:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:usw-pro-aggregation:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:ui:unifi_uap_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.5.53
     OR
          cpe:2.3:h:ui:u6\+:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-enterprise:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-enterprise-iw:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-extender:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-iw:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-lite:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-lr:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-mesh:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:u6-pro:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:uap-ac-iw:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:uap-ac-lite:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:uap-ac-lr:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:uap-ac-m:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:uap-ac-m-pro:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:uap-ac-pro:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:ubb:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:ubb-xg:-:*:*:*:*:*:*:*
          cpe:2.3:h:ui:uwb-xg:-:*:*:*:*:*:*:*
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-77
Changed Reference Type
https://community.ui.com/releases/Security-Advisory-Bulletin-035-035/91107858-9884-44df-b1c6-63c6499f6e56 No Types Assigned
https://community.ui.com/releases/Security-Advisory-Bulletin-035-035/91107858-9884-44df-b1c6-63c6499f6e56 Issue Tracking, Vendor Advisory