9.8

CVE-2022-35733

Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
UnimoUdr-ja1004 Firmware Version <= 1.0.20.13
   UnimoUdr-ja1004 Version-
UnimoUdr-ja1008 Firmware Version <= 1.0.20.13
   UnimoUdr-ja1008 Version-
UnimoUdr-ja1016 Firmware Version <= 2.0.20.13
   UnimoUdr-ja1016 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.25% 0.655
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

http://www.unimo.co.jp/table_notice/index.php?act=1&resid=1643590226-637355
Vendor Advisory
https://jvn.jp/en/vu/JVNVU90821877/index.html
Third Party Advisory