PT-2020-20012 · Ubiquiti · Unifi Protect

Published

2020-07-02

·

Updated

2020-07-09

·

CVE-2020-8188

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UniFi Protect firmware versions prior to 1.13.3 UniFi Protect firmware versions prior to 1.14.10
Description The issue allows view-only users to execute certain custom commands, enabling them to assign themselves unauthorized roles and escalate their privileges.
Recommendations For UniFi Protect firmware versions prior to 1.13.3, update to version 1.13.3 or later. For UniFi Protect firmware versions prior to 1.14.10, update to version 1.14.10 or later.

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8188

Affected Products

Unifi Protect