CVE-2022-23771

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
17/10/2022
Last modified:
19/10/2022

Description

This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:iptime:nas1dual_firmware:*:*:*:*:*:*:*:* 1.4.86 (excluding)
cpe:2.3:h:iptime:nas1dual:-:*:*:*:*:*:*:*
cpe:2.3:o:iptime:nas2dual_firmware:*:*:*:*:*:*:*:* 1.4.86 (excluding)
cpe:2.3:h:iptime:nas2dual:-:*:*:*:*:*:*:*
cpe:2.3:o:iptime:nas4dual_firmware:*:*:*:*:*:*:*:* 1.4.86 (excluding)
cpe:2.3:h:iptime:nas4dual:-:*:*:*:*:*:*:*