SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-23227

NUUO NVRmini2 Devices Missing Authentication Vulnerability

KEVCRITICAL 9.8EPSS 48.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 January 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
48.50% probability · 99th percentile
CISA KEV
Listed 18 December 2024 · due 8 January 2025
Weakness
CWE-306
Affected
nuuo/nvrmini2 firmware
Source
cve@mitre.org

CISA notes

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. https://nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter_NVRmini-2-and-NVRsolo-series.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2022-23227

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.