Remote Code Execution Vulnerability in Voltronic Power ViewPower Pro
CVE-2023-51593

9.8CRITICAL

Key Information:

Vendor
CVE Published:
3 May 2024

What is CVE-2023-51593?

A vulnerability in Voltronic Power ViewPower Pro allows remote attackers to execute arbitrary code without requiring authentication. Due to a flaw in the Struts2 dependency, the use of an insecure library enables expression language injection. This exploit can allow an attacker to run code with LOCAL SERVICE privileges, potentially compromising the security of the affected systems.

Affected Version(s)

ViewPower Pro 2.0-22165

References

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.