CVE-2022-23227
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 14, 2022
Updated: Jan 3, 2025
CWE ID 306
Summary
CVE-2022-23227 is a vulnerability affecting NUUO NVRmini2 models up to version 3.11. An unauthenticated attacker can exploit this flaw by uploading an encrypted TAR archive through the unsecured import feature. However, the handling of imported users in the 'handle_import_user.php' file is missing authentication checks, allowing the attacker to add new users without authorization. If an attacker also leverages CVE-2011-5325, they can overwrite arbitrary files under the web root, potentially leading to code execution with root privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Nuuo Nvrmini 2 Firmware
Affected Vendors
- Nuuo