CVE-2022-23227

CVE Published 2022-01-14
Related CWE(s) CWE-306: Missing Authentication for Critical Function
Related Vendor(s) nuuo
Related Product(s) nvrmini2_firmware
Exploitation Reported (CISA KEV) 2024-12-18
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References