Skip to content
COOEY

EXPOSURES › CVE-2022-23227

CVE-2022-23227

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-23227 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedauth-bypasssupply-chain

NUUO NVRmini2 devices allow unauthenticated attackers to add arbitrary users via encrypted TAR archives, enabling unauthorized access to surveillance systems.

This missing authentication vulnerability permits attackers to bypass login requirements and create new user accounts on NUUO NVRmini2 devices, directly violating CMMC/NIST 800-171 access control requirements. Defense-industrial-base organizations must patch these devices immediately to prevent unauthorized surveillance system access and potential data exfiltration.

Shame score — The vulnerability allows unauthenticated user creation, representing a critical access control failure that could enable lateral movement within surveillance systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.