← All CVEs

CVE-2022-23227

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added 2024-12-18Remediation due 2025-01-08

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

9.8
CVSS
48.5%
EPSS (exploit prob.)
99th
EPSS percentile
2022-01-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Affected products

VendorProductAffected versions
nuuonvrmini2_firmware<= 3.11.0
nuuonvrmini2all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-23227