A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share Livestream" link to maintain access to the corresponding livestream subsequent to such link becoming disabled.
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Mon, 19 May 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share Livestream" link to maintain access to the corresponding livestream subsequent to such link becoming disabled. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2025-05-19T01:25:08.458Z
Updated: 2025-05-19T14:45:25.014Z
Reserved: 2025-01-12T01:00:00.648Z
Link: CVE-2025-23164
Updated: 2025-05-19T14:44:46.092Z
Status : Awaiting Analysis
Published: 2025-05-19T02:15:17.253
Modified: 2025-05-19T15:15:23.207
Link: CVE-2025-23164
No data.
ReportizFlow