ID

VAR-202007-1163


CVE

CVE-2020-8213


TITLE

Ubiquiti Networks UniFi Protect information disclosure vulnerability

Trust: 1.2

sources: CNVD: CNVD-2020-46795 // CNNVD: CNNVD-202007-1741

DESCRIPTION

An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing. UniFi Protect Includes a vulnerability related to information leakage due to error messages.Information may be obtained. Ubiquiti Networks UniFi Protect is a network video recorder from Ubiquiti Networks. The vulnerability stems from a configuration error in the network system or product during operation. Unauthorized attackers can use vulnerabilities to obtain sensitive information about affected components

Trust: 2.16

sources: NVD: CVE-2020-8213 // JVNDB: JVNDB-2020-008975 // CNVD: CNVD-2020-46795

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-46795

AFFECTED PRODUCTS

vendor:uimodel:unifi protectscope:lteversion:1.13.3

Trust: 1.0

vendor:uimodel:unifi protectscope:eqversion:1.13.4-beta.5

Trust: 0.8

vendor:ubiquitimodel:networks ubiquiti networks unifi protect <1.13.4-beta.5scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-46795 // JVNDB: JVNDB-2020-008975 // NVD: CVE-2020-8213

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8213
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-008975
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-46795
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202007-1741
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-8213
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-008975
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-46795
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-8213
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-008975
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-46795 // JVNDB: JVNDB-2020-008975 // CNNVD: CNNVD-202007-1741 // NVD: CVE-2020-8213

PROBLEMTYPE DATA

problemtype:CWE-209

Trust: 1.8

sources: JVNDB: JVNDB-2020-008975 // NVD: CVE-2020-8213

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202007-1741

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202007-1741

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-008975

PATCH

title:Security advisory bulletin 013url:https://community.ui.com/releases/Security-advisory-bulletin-013-013/56d4d616-4afd-40ee-863f-319b7126ed84

Trust: 0.8

sources: JVNDB: JVNDB-2020-008975

EXTERNAL IDS

db:NVDid:CVE-2020-8213

Trust: 3.0

db:JVNDBid:JVNDB-2020-008975

Trust: 0.8

db:CNVDid:CNVD-2020-46795

Trust: 0.6

db:NSFOCUSid:47573

Trust: 0.6

db:CNNVDid:CNNVD-202007-1741

Trust: 0.6

sources: CNVD: CNVD-2020-46795 // JVNDB: JVNDB-2020-008975 // CNNVD: CNNVD-202007-1741 // NVD: CVE-2020-8213

REFERENCES

url:https://community.ui.com/releases/security-advisory-bulletin-013-013/56d4d616-4afd-40ee-863f-319b7126ed84

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-8213

Trust: 1.4

url:https://community.ui.com/releases/unifi-protect-1-13-4-beta-2/405d4cf9-e538-48d1-8825-36657a692f3f

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8213

Trust: 0.8

url:https://community.ui.com/questions/cloudkey-plus-ck-how-to-get-on-the-beta-release-channel/c26acdf8-321c-49b6-8f0d-9d7d99bf6aee

Trust: 0.6

url:http://www.nsfocus.net/vulndb/47573

Trust: 0.6

sources: CNVD: CNVD-2020-46795 // JVNDB: JVNDB-2020-008975 // CNNVD: CNNVD-202007-1741 // NVD: CVE-2020-8213

SOURCES

db:CNVDid:CNVD-2020-46795
db:JVNDBid:JVNDB-2020-008975
db:CNNVDid:CNNVD-202007-1741
db:NVDid:CVE-2020-8213

LAST UPDATE DATE

2024-11-23T22:21:04.762000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-46795date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-008975date:2020-10-13T00:00:00
db:CNNVDid:CNNVD-202007-1741date:2020-08-11T00:00:00
db:NVDid:CVE-2020-8213date:2024-11-21T05:38:30.960

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-46795date:2020-08-18T00:00:00
db:JVNDBid:JVNDB-2020-008975date:2020-10-13T00:00:00
db:CNNVDid:CNNVD-202007-1741date:2020-07-30T00:00:00
db:NVDid:CVE-2020-8213date:2020-07-30T13:15:11.610