Local Privilege Escalation Vulnerability in Voltronic ViewPower Pro MySQL Configuration
CVE-2023-51588

7.8HIGH

Key Information:

Vendor
CVE Published:
3 May 2024

What is CVE-2023-51588?

A security vulnerability has been identified in Voltronic Power's ViewPower Pro due to the use of hard-coded credentials within its MySQL configuration. This flaw enables local attackers, who already have access to the system, to escalate their privileges and execute arbitrary code with SYSTEM-level rights. The exploitation starts with obtaining low-privileged access, followed by leveraging the hard-coded credentials to gain unauthorized control over the application, potentially compromising the system's integrity.

Affected Version(s)

ViewPower Pro 2.0-22165

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.