CVE-2021-33818
https://notcve.org/view.php?id=CVE-2021-33818
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service. Se ha detectado un problema en UniFi Protect G3 FLEX Camera versión UVC.v4.30.0.67. Unos atacantes pueden usar la herramienta slowhttptest para enviar peticiones HTTP incompletas, lo que podría hacer que el servidor siga esperando a que el paquete termine la conexión, hasta que sean agotados sus recursos. • https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33818.md https://github.com/shekyan/slowhttptest https://store.ui.com/collections/unifi-protect-cameras/products/unifi-video-g3-flex-camera • CWE-400: Uncontrolled Resource Consumption •
CVE-2021-33820
https://notcve.org/view.php?id=CVE-2021-33820
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67.Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service. Se ha detectado un problema en UniFi Protect G3 FLEX Camera versión UVC.v4.30.0.67. El atacante puede enviar una gran cantidad de paquetes TCP SYN para hacer que los recursos del servicio web sean agotados. Entonces, el servidor web sufre una denegación de servicio • https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33820.md https://linuxhint.com/hping3 https://store.ui.com/collections/unifi-protect-cameras/products/unifi-video-g3-flex-camera •