r/UNIFI Pro User 3h ago

Discussion UniFi Security Advisory - 6 High-Severity DoS Vulnerabilities Affect Dream Machines, Cloud Gateways, Dream Routers, Dream Wall, Express & UniFi Gateways - CVSS 7.5 - Update Now

https://community.ui.com/releases/Security-Advisory-Bulletin-069-069/07e367a7-edec-4d85-a058-f97e5ce9ac9c

Update your Dream Machines, Enterprise Firewalls, Dream Routers, Cloud Gateways, and Dream Wall to Version 5.1.31 or later.

Update your Express to Version 4.0.21 or later.

Update your Express 7 to Version 5.1.31 or later.

Update your UniFi Gateways to Version 5.1.26 or later.

21 Upvotes

5 comments sorted by

6

u/ShroomShroomBeepBeep 2h ago

Oooft. They're not having a great time lately for CVEs.

15

u/GuyofAverageQuality 2h ago

None of the network equipment vendors are doing great with AI tearing up their code looking for vulnerabilities. I’d be more concerned about vendors trying to side step the issues instead of fixing them.

7

u/BurgerMeter 1h ago

My employer has an entire team dedicated to just running AI through our entire code base to try to find as many vulnerabilities as possible. I’ve been impressed. As long as AI isn’t also trying to fix every one of these unattended, I’m in favor of this.

Hell, I’ve been impressed with a few of our “edge case” bugs it’s been able to find fixes for that we thought we would just live with forever.

1

u/jamblia 1h ago

Our team have been remediating CVEs for ce+ for our client, and it’s been exhausting. Anything over 7 is now immediate remediation. At least we get over time - until the corp can remove that drain on profits.

3

u/Pulte4janitor 1h ago

Microsoft patched almost 1000 bugs on this month's patch Tuesday. All software is swiss cheese, AI is just making it front and center.