PT-2021-20332 · Ubiquiti · Unifi Protect G3 Flex Camera

Guan Yu Lai

+2

·

Published

2021-06-18

·

Updated

2021-06-24

·

CVE-2021-33818

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: UniFi Protect G3 FLEX Camera version UVC.v4.30.0.67
Description: An issue was discovered in the UniFi Protect G3 FLEX Camera, where attackers can use the slowhttptest tool to send incomplete HTTP requests. This could make the server keep waiting for the packet to finish the connection until its resources are exhausted, resulting in a denial-of-service.
Recommendations: For UniFi Protect G3 FLEX Camera version UVC.v4.30.0.67, consider restricting access to the web server to minimize the risk of exploitation until a patch is available. As a temporary workaround, limiting the number of concurrent connections to the server may help mitigate the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33818

Affected Products

Unifi Protect G3 Flex Camera