Lucene search

K
cveMitreCVE-2021-33818
HistoryJun 18, 2021 - 7:15 p.m.

CVE-2021-33818

2021-06-1819:15:07
CWE-400
mitre
web.nvd.nist.gov
75
unifi protect
g3 flex camera
cve-2021-33818
nvd
denial-of-service
slowhttptest
http request

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

59.2%

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

Affected configurations

Nvd
Node
uicamera_g3_flexMatch-
AND
uicamera_g3_flex_firmwareMatchuvc.v4.30.0.67
VendorProductVersionCPE
uicamera_g3_flex-cpe:2.3:h:ui:camera_g3_flex:-:*:*:*:*:*:*:*
uicamera_g3_flex_firmwareuvc.v4.30.0.67cpe:2.3:o:ui:camera_g3_flex_firmware:uvc.v4.30.0.67:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

59.2%

Related for CVE-2021-33818