Security readout for executives and security teams
Plain-English summary
CVE-2021-22944 lets a view-only UniFi Protect user with network access gain owner-level privileges. That turns a supposedly limited account into full control of the Protect application. The issue affects UniFi Protect application version 1.18.1 and earlier and is fixed in 1.19.0 and later.
Executive priority
Treat as high priority where UniFi Protect is still on 1.18.1 or earlier. The business risk is privilege escalation from limited surveillance access to owner-level control.
Technical view
The flaw is a privilege escalation in UniFi Protect application 1.18.1 and earlier. The stated attacker profile is authenticated with a view-only role plus network access. Successful exploitation grants privileges equivalent to the application owner. The source bundle does not provide CVSS, CWE, exploit details, or broader affected product data.
Likely exposure
Exposure is likely limited to organizations running UniFi Protect application 1.18.1 or earlier, especially where view-only users can reach the Protect application over the network.
Exploitation context
The provided sources do not support claims of active exploitation. KEV status is false, and the bundle does not cite public exploit activity or exploitation telemetry.
Researcher notes
Evidence is sparse. The record identifies the affected version boundary and fixed version, but does not provide CVSS, CWE, root cause, proof-of-concept status, or detailed mitigations beyond upgrading.
Mitigation direction
- Upgrade UniFi Protect application to version 1.19.0 or later.
- Review the vendor security advisory before operational changes.
- Remove unnecessary view-only accounts from UniFi Protect.
- Restrict network access to UniFi Protect management interfaces.
Validation and detection
- Inventory UniFi Protect deployments and record application versions.
- Confirm no deployment runs version 1.18.1 or earlier.
- Review UniFi Protect users for unexpected view-only accounts.
- Verify management access is limited to intended networks.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-22944 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://community.ui.com/releases/Security-Advisory-Bulletin-019-019/90a00abe-d6b6-43c6-92d4-0a0342f1506fCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
