« Volver al listado

CVE-2022-23771

Estado: ModificadaAlta (8.8)—

This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23771",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-23771",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-09T14:26:23.184747Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vuln@krcert.or.kr",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@krcert.or.kr",
      "affectedData": [
        {
          "vendor": "EFM Networks Co., Ltd",
          "product": "NAS1dual, NAS2dual, NAS4dual",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.4.86",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux, Windows and etc.."
          ]
        }
      ]
    }
  ],
  "published": "2022-10-17T16:15:20.857",
  "references": [
    {
      "url": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66964",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vuln@krcert.or.kr"
    },
    {
      "url": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66964",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vuln@krcert.or.kr",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges."
    },
    {
      "lang": "es",
      "value": "Esta vulnerabilidad es producida en las páginas relacionadas con la creación y eliminación de cuentas de usuario de los productos IPTIME NAS. La vulnerabilidad podría ser explotada por una falta de comprobación cuando es realizada una petición POST a esta página. Un atacante puede usar esta vulnerabilidad para o eliminar cuentas de usuario, o para escalar privilegios de usuario arbitrarios"
    }
  ],
  "lastModified": "2026-06-17T04:30:46.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas1dual_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90965263-2D84-4742-B60E-0A6738D9F329",
              "versionEndExcluding": "1.4.86"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas1dual:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2ACEC464-70B3-452B-A1A3-594C697E3AB3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas2dual_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C67D4CA9-5991-4E37-B3E4-F39A49E949E8",
              "versionEndExcluding": "1.4.86"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas2dual:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "271D21D5-A55E-4D4F-8473-5A7A67573DEA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:iptime:nas4dual_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D302186C-3FF6-49F2-9622-ED3FB06F9EE1",
              "versionEndExcluding": "1.4.86"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:iptime:nas4dual:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0429CC1A-B95C-4FB0-90D6-D6CAD8E1CC14"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vuln@krcert.or.kr"
}