VulnerabilityModified
CVE-2018-1150
NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.
HIGH 7.3EPSS 1.86%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.
- CVSS 3.0
- 7.3 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- nuuo/nvrmini2 firmware
- Source
- vulnreport@tenable.com
References
- http://www.securityfocus.com/bid/105720Third Party Advisory, VDB Entry
- https://www.nuuo.com/backend/CKEdit/upload/files/NUUO_NVRsolo_v3_9_1_Release%20note.pdfRelease Notes, Vendor Advisory
- https://www.tenable.com/security/research/tra-2018-25Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/105720Third Party Advisory, VDB Entry
- https://www.nuuo.com/backend/CKEdit/upload/files/NUUO_NVRsolo_v3_9_1_Release%20note.pdfRelease Notes, Vendor Advisory
- https://www.tenable.com/security/research/tra-2018-25Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.