PT-2020-20027 · Ubiquiti · Unifi Protect

Published

2020-07-30

·

Updated

2020-08-05

·

CVE-2020-8213

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions UniFi Protect versions prior to 1.13.4-beta.5
Description An information exposure issue allows unauthenticated attackers to access valid usernames for the UniFi Protect web application through differences in HTTP response codes and response timing.
Recommendations For versions prior to 1.13.4-beta.5, update to version 1.13.4-beta.5 or later to resolve the issue.

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8213

Affected Products

Unifi Protect