Remote Authentication Bypass Vulnerability in Voltronic Power ViewPower Pro
CVE-2023-51573
9.8CRITICAL
What is CVE-2023-51573?
An authentication bypass vulnerability exists in Voltronic Power's ViewPower Pro due to the exposure of the updateManagerPassword function. This flaw allows remote attackers to circumvent standard authentication mechanisms, providing potential access to sensitive functionalities without legitimate credentials. The vulnerability targets specific versions of the ViewPower Pro software, making it crucial for users to patch affected installations promptly to mitigate any risk of exploitation.
Affected Version(s)
ViewPower Pro 2.0-22165
References
EPSS Score
45% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
