Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-29040 | The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request with a URL to firmware update information. If the version field contains ..\ character sequences, the destination file path to save the firmware can be manipulated to be outside the intended destination directory tree. Fixed in UniFi Video Controller v3.10.3 and newer. |
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T09:48:25.776Z
Reserved: 2020-01-28T00:00:00.000Z
Link: CVE-2020-8144
No data.
Status : Modified
Published: 2020-04-01T23:15:13.813
Modified: 2026-06-17T03:25:56.203
Link: CVE-2020-8144
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
EUVD