CVE-2022-23771
17.10.2022, 16:15
This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.
Vendor | Product | Version |
---|---|---|
iptime | nas1dual_firmware | 𝑥 < 1.4.86 |
iptime | nas2dual_firmware | 𝑥 < 1.4.86 |
iptime | nas4dual_firmware | 𝑥 < 1.4.86 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration