← Back to browse · API

CVE-2022-23227

Severity
CRITICAL
CVSS
9.8
EPSS
0.49431
Risk score
81.5
CISA KEV
Yes
PoC
No
Published
2024-12-18
Modified
2024-12-18
First seen
2026-08-07
Aliases
EUVD-2022-28314, GHSA-5F63-P3W5-JPHC
Products
NUUO:NVRmini2 Devices, n/a:n/a n/a
Sources
euvd EUVD-2022-28314
cisa.gov CVE-2022-23227

Description

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

References