CVE-2021-33818
Last modified
CVE-2021-33818 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ui | Camera G3 Flex Firmware | uvc.v4.30.0.67 |
References
- https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33818.mdExploit, Third Party Advisory
- https://github.com/shekyan/slowhttptestThird Party Advisory
- https://store.ui.com/collections/unifi-protect-cameras/products/unifi-video-g3-flex-cameraProduct, Vendor Advisory
- https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33818.mdExploit, Third Party Advisory
- https://github.com/shekyan/slowhttptestThird Party Advisory
- https://store.ui.com/collections/unifi-protect-cameras/products/unifi-video-g3-flex-cameraProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33818?
How severe is CVE-2021-33818?
How do I fix CVE-2021-33818?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33805Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-33806The BDew BdLib library before 1.16.1.7 for Minecraft allows …9.8
- CVE-2021-33807Cartadis Gespage through 8.2.1 allows Directory Traversal in…7.5
- CVE-2021-33813An XXE issue in SAXBuilder in JDOM through 2.0.6 allows atta…7.5
- CVE-2021-33815dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an o…8.8
- CVE-2021-33816The website builder module in Dolibarr 13.0.2 allows remote …9.8
- CVE-2021-3382Stack buffer overflow vulnerability in gitea 1.9.0 through 1…7.5
- CVE-2021-33820An issue was discovered in UniFi Protect G3 FLEX Camera Vers…7.5
- CVE-2021-33822An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E…7.5
- CVE-2021-33823An issue was discovered on MOXA Mgate MB3180 Version 2.1 Bui…7.5
- CVE-2021-33824An issue was discovered on MOXA Mgate MB3180 Version 2.1 Bui…7.5
- CVE-2021-33827The files_antivirus component before 1.0.0 for ownCloud allo…7.2
Are you affected by CVE-2021-33818?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
