CVE-2021-22944

A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role and network access to gain the same privileges as the owner of the UniFi Protect application. This vulnerability is fixed in UniFi Protect application V1.19.0 and later.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ui:unifi_protect:*:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-noinfo

09 Sep 2021, 00:13

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.7
v3 : 8.0
CPE cpe:2.3:a:ui:unifi_protect:*:*:*:*:*:*:*:*
CWE CWE-269
References (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-019-019/90a00abe-d6b6-43c6-92d4-0a0342f1506f - (MISC) https://community.ui.com/releases/Security-Advisory-Bulletin-019-019/90a00abe-d6b6-43c6-92d4-0a0342f1506f - Vendor Advisory

31 Aug 2021, 17:22

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-31 17:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-22944

Mitre link : CVE-2021-22944

CVE.ORG link : CVE-2021-22944


JSON object : View

Products Affected

ui

  • unifi_protect