CVE-2020-8213: Medium severity unifi protect vulnerability
Published Jul 30, 2020
·Updated
An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing.
Affected Software
1 affected component
UI Unifi Protect<=1.13.3
Event History
Jul 30, 2020
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this information exposure vulnerability?
The vulnerability ID is CVE-2020-8213.
2
What is the severity of CVE-2020-8213?
The severity of CVE-2020-8213 is medium with a CVSS score of 5.3.
3
What is the affected software version for CVE-2020-8213?
The affected software version for CVE-2020-8213 is UniFi Protect before v1.13.4-beta.5.
4
How can unauthenticated attackers exploit CVE-2020-8213?
Unauthenticated attackers can exploit CVE-2020-8213 by gaining access to valid usernames for the UniFi Protect web application via HTTP response code and response timing.
5
Is there a fix available for CVE-2020-8213?
Yes, a fix is available for CVE-2020-8213 in UniFi Protect v1.13.4-beta.5 and later versions.