EXPOSURES › CVE-2022-23227
CVE-2022-23227
HIGH ⌖ ON CISA KEV · EXPLOITEDNUUO NVRmini2 devices allow unauthenticated attackers to add arbitrary users via encrypted TAR archives, enabling unauthorized access to surveillance systems.
This missing authentication vulnerability permits attackers to bypass login requirements and create new user accounts on NUUO NVRmini2 devices, directly violating CMMC/NIST 800-171 access control requirements. Defense-industrial-base organizations must patch these devices immediately to prevent unauthorized surveillance system access and potential data exfiltration.
Shame score — The vulnerability allows unauthenticated user creation, representing a critical access control failure that could enable lateral movement within surveillance systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.