Impact
A buffer overflow exists in the UniFi Protect Application’s discovery protocol that, when triggered by a crafted packet, causes the application to reboot. This flaw exploits improper bounds checking (CWE‑119) and results in a loss of service rather than compromising data confidentiality or integrity.
Affected Systems
The vulnerability affects Ubiquiti Inc’s UniFi Protect Application running version 6.1.79 and all earlier releases. Users of this product should verify their deployment version to determine applicability.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit activity. The attacker must be on the same local network or have sufficient network proximity to send the malformed discovery packet, making the attack vector likely to be adjacent network access.
OpenCVE Enrichment