CVE-2017-0913

MEDIUM

Ubiquiti UCRM 2.3.0-2.7.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://hackerone.com/reports/301406

Scores

CVSS v3 4.7
EPSS 0.0006
EPSS Percentile 16.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-732
Status published
Products (1)
ubnt/ucrm 2.3.0 - 2.7.7
Published Jul 03, 2018
Tracked Since Feb 18, 2026