Loading
Generated remediation guidance and an executive summary. No account required.
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and obtain credentials by exploiting the insecure SSL host verification mechanism in the SMTP certificate validation process.
No affected products information available.
Use CWE-295 to widen CVE-2019-25652 into its surrounding weakness, vendor, and product context.