PT-2018-10616 · Nuuo · Nvrmini2

Published

2018-09-19

·

Updated

2019-10-03

·

CVE-2018-1150

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NUUO's NVRMini2 versions 3.8.0 and below
Description The issue allows an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.
Recommendations For versions 3.8.0 and below, remove the /tmp/moses file to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-1150

Affected Products

Nvrmini2