10
CVSSv2

CVE-2022-23227

Published: 14/01/2022 Updated: 21/01/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

NUUO NVRmini2 up to and including 3.11 allows an unauthenticated malicious user to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nuuo nvrmini2_firmware