← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-8188

We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prior according to the description below:View only users can run certain custom commands which allows them to assign themselves unauthorized roles and escalate their privileges.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:1.34%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-77 ↗Command Injection - Generic (CWE-77)

Affected Products & Versions

Vendor Product Affected Versions
ui unifi_protect_firmware all
ui unifi_protect all
ui unifi_cloud_key_plus all
ui unifi_dream_machine_pro all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.342%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2020-01-28T00:00:00
Published2020-07-02T18:35:14
Last Updated2024-08-04T09:56:28

LINK COPIED TO CLIPBOARD