PT-2020-20012 · Ubiquiti · Unifi Protect
Published
2020-07-02
·
Updated
2020-07-09
·
CVE-2020-8188
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UniFi Protect firmware versions prior to 1.13.3
UniFi Protect firmware versions prior to 1.14.10
Description
The issue allows view-only users to execute certain custom commands, enabling them to assign themselves unauthorized roles and escalate their privileges.
Recommendations
For UniFi Protect firmware versions prior to 1.13.3, update to version 1.13.3 or later.
For UniFi Protect firmware versions prior to 1.14.10, update to version 1.14.10 or later.
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unifi Protect