First published: Tue Feb 23 2021(Updated: )
UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
UniFi Protect Controller | <1.17.1 | |
UniFi Cloud Key Gen2 Plus | ||
UniFi Dream Machine Pro | ||
UniFi Network Video Recorder |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22882 is a vulnerability in UniFi Protect before v1.17.1 that allows an attacker to use spoofed cameras to perform a denial-of-service attack.
The severity of CVE-2021-22882 is high, with a CVSS score of 7.5.
UniFi Protect versions before v1.17.1 are affected by CVE-2021-22882.
An attacker can exploit CVE-2021-22882 by using spoofed cameras to perform a denial-of-service attack on the UniFi Protect controller, potentially causing it to crash.
No, the UniFi Cloud Key Plus, UniFi Dream Machine Pro, and UniFi Network Video Recorder are not affected by CVE-2021-22882.
You can find more information about CVE-2021-22882 in the security advisory bulletin and the HackerOne report linked in the references.