Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability
CVE-2023-51571
7.5HIGH
What is CVE-2023-51571?
The vulnerability involves a denial-of-service condition in the SocketService module of Voltronic Power's ViewPower Pro. This module, which defaults to listening on UDP port 41222, does not require authentication, allowing unauthorized attackers to exploit this flaw. By leveraging the lack of authentication, attackers can disrupt the normal operations of the system, leading to potential service outages. The absence of necessary security measures in this part of the software makes it particularly susceptible to remote exploitation.
Affected Version(s)
ViewPower Pro 2.0-22165
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
