10
CVE-2022-23227
- EPSS 52.85%
- Published 14.01.2022 18:15:10
- Last modified 13.03.2025 15:40:29
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
Data is provided by the National Vulnerability Database (NVD)
Nuuo ≫ Nvrmini2 Firmware Version <= 3.11.0
18.12.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog
NUUO NVRmini2 Devices Missing Authentication Vulnerability
VulnerabilityNUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
DescriptionThe impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 52.85% | 0.979 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.