8.8
CVSSv3

CVE-2022-23771

Published: 17/10/2022 Updated: 19/10/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

iptime nas1dual firmware

iptime nas2dual firmware

iptime nas4dual firmware