Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability
CVE-2023-51571

7.5HIGH

Key Information:

Vendor
CVE Published:
1 April 2024

What is CVE-2023-51571?

The vulnerability involves a denial-of-service condition in the SocketService module of Voltronic Power's ViewPower Pro. This module, which defaults to listening on UDP port 41222, does not require authentication, allowing unauthorized attackers to exploit this flaw. By leveraging the lack of authentication, attackers can disrupt the normal operations of the system, leading to potential service outages. The absence of necessary security measures in this part of the software makes it particularly susceptible to remote exploitation.

Affected Version(s)

ViewPower Pro 2.0-22165

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.