RaqibCTI
CVE

CVE-2022-23227

P2
NUUO NVRmini2 Devices Missing Authentication Vulnerability
NUUO · NVRmini2 Devices
Date added (CISA)
2024-12-18
Remediation due
2025-01-08
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

Source: NVD ↗ · CISA KEV Catalog ↗