Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8188

Опубликовано: 02 июл. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prior according to the description below:View only users can run certain custom commands which allows them to assign themselves unauthorized roles and escalate their privileges.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:ui:unifi_protect_firmware:*:*:*:*:*:*:*:*
Версия до 1.13.2 (включая)
cpe:2.3:h:ui:unifi_protect:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:ui:unifi_protect_firmware:*:*:*:*:*:*:*:*
Версия до 1.14.9 (включая)

Одно из

cpe:2.3:h:ui:unifi_cloud_key_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00944
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-77
CWE-78

Связанные уязвимости

github
больше 3 лет назад

We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prior according to the description below:View only users can run certain custom commands which allows them to assign themselves unauthorized roles and escalate their privileges.

EPSS

Процентиль: 76%
0.00944
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-77
CWE-78