CVE-2022-23227

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 14, 2022
Updated: Jan 3, 2025
CWE ID 306

Summary

CVE-2022-23227 is a vulnerability affecting NUUO NVRmini2 models up to version 3.11. An unauthenticated attacker can exploit this flaw by uploading an encrypted TAR archive through the unsecured import feature. However, the handling of imported users in the 'handle_import_user.php' file is missing authentication checks, allowing the attacker to add new users without authorization. If an attacker also leverages CVE-2011-5325, they can overwrite arbitrary files under the web root, potentially leading to code execution with root privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nuuo Nvrmini 2 Firmware

Affected Vendors

  • Nuuo