6
CVSSv2

CVE-2014-2227

Published: 25/07/2014 Updated: 10/06/2019
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) prior to 3.0.1 does not restrict access to the application, which allows remote malicious users to bypass the Same Origin Policy via a crafted SWF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ui unifi video

Exploits

source: wwwsecurityfocuscom/bid/68866/info UniFi Video is prone to a security-bypass vulnerability An authenticated attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions This may lead to further attacks UniFi Video 213 is vulnerable; other versions may also be affected // Custom ...
Ubiquiti AirVision Controller version 213 suffers from an overly permissive default crossdomainxml file ...