Remote Code Execution Vulnerability in Voltronic Power ViewPower Pro
CVE-2023-51572

9.8CRITICAL

Key Information:

Vendor
CVE Published:
1 April 2024

What is CVE-2023-51572?

The vulnerability in Voltronic Power's ViewPower Pro is rooted in the getMacAddressByIP function, which fails to adequately validate user inputs prior to executing system commands. This oversight enables remote attackers to inject malicious commands that would execute with the privileges of the system user. Given that authentication is not a prerequisite for exploiting this vulnerability, unauthorized users can gain the ability to execute arbitrary code, leading to potential system compromise and unauthorized control over affected installations.

Affected Version(s)

ViewPower Pro 2.0-22165

References

EPSS Score

38% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.