« Volver al listado

CVE-2022-35733

Estado: ModificadaCrítica (9.8)—

Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-35733",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "UNIMO Technology Co., Ltd",
          "product": "UNIMO Technology digital video recorders UDR-JA1004/JA1008/JA1016 and UDR-JA1016",
          "versions": [
            {
              "status": "affected",
              "version": "UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-23T02:15:07.503",
  "references": [
    {
      "url": "http://www.unimo.co.jp/table_notice/index.php?act=1&resid=1643590226-637355",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/vu/JVNVU90821877/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.unimo.co.jp/table_notice/index.php?act=1&resid=1643590226-637355",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jvn.jp/en/vu/JVNVU90821877/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface."
    },
    {
      "lang": "es",
      "value": "Una falta de autenticación para la vulnerabilidad de la función crítica en los grabadores de vídeo digital de UNIMO Technology (versiones de firmware UDR-JA1004/JA1008/JA1016 versiones v1.0.20.13 y anteriores, y versiones de firmware UDR-JA1016 v2.0.20.13 y anteriores) permite a un atacante remoto no autenticado ejecutar un comando arbitrario del Sistema Operativo mediante el envío de una petición especialmente diseñada a la interfaz web del dispositivo afectado."
    }
  ],
  "lastModified": "2026-06-17T04:52:08.907",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:unimo:udr-ja1004_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EBDB7B7-0B10-46EB-BE94-9AF036778D81",
              "versionEndIncluding": "1.0.20.13"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:unimo:udr-ja1004:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DD4FF086-3812-43FF-86A3-6A464612AEE0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:unimo:udr-ja1008_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B92067E5-4411-4A8B-BD49-F5937EA16089",
              "versionEndIncluding": "1.0.20.13"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:unimo:udr-ja1008:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C6574581-471F-4812-8FFE-F41923C5B7EB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:unimo:udr-ja1016_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "799CC776-530D-4CD6-B7EE-C8A6963A6E7B",
              "versionEndIncluding": "2.0.20.13"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:unimo:udr-ja1016:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "62CF8836-F7F4-43CB-BA04-FF506DFB53F9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}