Remote Code Execution Vulnerability in Voltronic Power ViewPower Pro
CVE-2023-51584

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-51584?

A vulnerability in Voltronic Power's ViewPower Pro allows remote attackers to execute arbitrary code through the shutdown method. This security flaw arises from the exposure of a dangerous method that can be exploited if an administrator triggers a shutdown operation. Exploiting this vulnerability requires user interaction, as it necessitates the activation of the shutdown process by an authenticated user, thereby placing a significant risk on installations of ViewPower Pro. This highlights the critical need for users to be vigilant and apply best security practices to mitigate potential attacks.

Affected Version(s)

ViewPower 1.04-21353

References

CVSS V3.0

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.