Remote Code Execution Vulnerability in Voltronic Power ViewPower
CVE-2023-51583

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-51583?

A remote code execution vulnerability has been identified in Voltronic Power’s ViewPower product, specifically within the UpsScheduler class. This security flaw arises from an exposed method that could be exploited by remote attackers to execute arbitrary code. Notably, the exploitation of this vulnerability does not necessitate any form of authentication, allowing unauthorized attackers to execute code with SYSTEM privileges. This situation underscores significant risks for organizations relying on the affected software, necessitating immediate attention to security protocols and updates.

Affected Version(s)

ViewPower 1.04.21353

References

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.