Remote Code Execution Vulnerability in Voltronic Power ViewPower Pro
CVE-2023-51570

9.8CRITICAL

Key Information:

Vendor
CVE Published:
1 April 2024

What is CVE-2023-51570?

The vulnerability in Voltronic Power's ViewPower Pro is a deserialization flaw within the RMI interface, which operates on TCP port 41009 by default. This flaw allows remote attackers to execute arbitrary code without requiring authentication. By exploiting the insufficient validation of user-supplied data, an attacker can execute commands with SYSTEM privileges, potentially leading to significant security breaches.

Affected Version(s)

ViewPower Pro 2.0-22165

References

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.