Skip to content

CVE-2014-2227

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0151 (1.5%)
Percentile: 81.3%
EPSS: 2026-05-06

Affects

ui:unifi_video

Technical description

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

Published: 7/25/2014, 7:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam