CVE-2022-23227
NUUO NVRmini2 Devices Missing Authentication Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 January 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 48.50% probability · 99th percentile
- CISA KEV
- Listed 18 December 2024 · due 8 January 2025
- Weakness
- CWE-306
- Affected
- nuuo/nvrmini2 firmware
- Source
- cve@mitre.org
CISA notes
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. https://nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter_NVRmini-2-and-NVRsolo-series.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2022-23227
References
- https://github.com/pedrib/PoC/blob/master/advisories/NUUO/nuuo_nvrmini_round2.mkdExploit, Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/16044Exploit, Issue Tracking, Third Party Advisory
- https://news.ycombinator.com/item?id=29936569Third Party Advisory
- https://portswigger.net/daily-swig/researcher-discloses-alleged-zero-day-vulnerabilities-in-nuuo-nvrmini2-recording-deviceExploit, Third Party Advisory
- https://github.com/pedrib/PoC/blob/master/advisories/NUUO/nuuo_nvrmini_round2.mkdExploit, Third Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/16044Exploit, Issue Tracking, Third Party Advisory
- https://news.ycombinator.com/item?id=29936569Third Party Advisory
- https://portswigger.net/daily-swig/researcher-discloses-alleged-zero-day-vulnerabilities-in-nuuo-nvrmini2-recording-deviceExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-23227US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.