CVE-2020-24755

In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This was tested in (Windows 7 x64/Windows 10 x64).
References
Link Resource
https://www.youtube.com/watch?v=T41h4yeh9dk Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ui:unifi_video:3.10.13:*:*:*:*:*:*:*

History

24 May 2021, 17:48

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.9
v3 : 7.8
CPE cpe:2.3:a:ui:unifi_video:3.10.13:*:*:*:*:*:*:*
CWE CWE-427
References (MISC) https://www.youtube.com/watch?v=T41h4yeh9dk - (MISC) https://www.youtube.com/watch?v=T41h4yeh9dk - Exploit, Third Party Advisory

17 May 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-17 22:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-24755

Mitre link : CVE-2020-24755

CVE.ORG link : CVE-2020-24755


JSON object : View

Products Affected

ui

  • unifi_video
CWE
CWE-427

Uncontrolled Search Path Element