login
quiescence.eu
Aller au contenu

CVE-2022-23227

NUUO NVRmini2 Devices Missing Authentication Vulnerability

n/a
CVSS
49.4%
EPSS (exploit prob.)
98.8%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2024-12-18
Added

Summary

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

Affected software

Vendor: NUUO  ·  Product: NVRmini2 Devices

Weakness types (CWE):

CWE-306

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in NUUO

CVENameEPSSExploited
CVE-2018-14933 NUUO NVRmini Devices OS Command Injection Vulnerability 93.7% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.