CVE-2021-33820

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67.Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:camera_g3_flex_firmware:uvc.v4.30.0.67:*:*:*:*:*:*:*
cpe:2.3:h:ui:camera_g3_flex:-:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-400 NVD-CWE-noinfo

24 Jun 2021, 19:44

Type Values Removed Values Added
References (MISC) https://linuxhint.com/hping3/ - (MISC) https://linuxhint.com/hping3/ - Third Party Advisory
References (MISC) https://store.ui.com/collections/unifi-protect-cameras/products/unifi-video-g3-flex-camera - (MISC) https://store.ui.com/collections/unifi-protect-cameras/products/unifi-video-g3-flex-camera - Product, Vendor Advisory
References (MISC) https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33820.md - (MISC) https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33820.md - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-400
CPE cpe:2.3:h:ui:camera_g3_flex:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:camera_g3_flex_firmware:uvc.v4.30.0.67:*:*:*:*:*:*:*

18 Jun 2021, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-18 19:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-33820

Mitre link : CVE-2021-33820

CVE.ORG link : CVE-2021-33820


JSON object : View

Products Affected

ui

  • camera_g3_flex_firmware
  • camera_g3_flex