Vulnerability Description
NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nuuo | Nvrmini2 Firmware | <= 3.8.0 |
| Nuuo | Nvrmini2 | - |
References
- http://www.securityfocus.com/bid/105720Third Party AdvisoryVDB Entry
- https://www.nuuo.com/backend/CKEdit/upload/files/NUUO_NVRsolo_v3_9_1_Release%20nRelease NotesVendor Advisory
- https://www.tenable.com/security/research/tra-2018-25ExploitThird Party Advisory
- http://www.securityfocus.com/bid/105720Third Party AdvisoryVDB Entry
- https://www.nuuo.com/backend/CKEdit/upload/files/NUUO_NVRsolo_v3_9_1_Release%20nRelease NotesVendor Advisory
- https://www.tenable.com/security/research/tra-2018-25ExploitThird Party Advisory
FAQ
What is CVE-2018-1150?
CVE-2018-1150 is a vulnerability with a CVSS score of 7.3 (HIGH). NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.
How severe is CVE-2018-1150?
CVE-2018-1150 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1150?
Check the references section above for vendor advisories and patch information. Affected products include: Nuuo Nvrmini2 Firmware, Nuuo Nvrmini2.