📦 Viewpower

by Voltronicpower

🔍 What is Viewpower?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-51595

CRITICAL CVSS 9.8 May 3, 2024

This is an unauthenticated SQL injection vulnerability in Voltronic Power ViewPower Pro that allows remote attackers to execute arbitrary code. Attackers can exploit this without credentials to run co...

CVE-2023-51590

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows unauthenticated remote attackers to upload arbitrary files to Voltronic Power ViewPower Pro systems, leading to remote code execution. Attackers can execute commands with LOC...

CVE-2023-51593

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Voltronic Power ViewPower Pro systems by exploiting expression language injection in the Struts2 dependency. Aff...

CVE-2023-51583

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Voltronic Power ViewPower installations. The flaw exists in the UpsScheduler class where ...

CVE-2023-51586

CRITICAL CVSS 9.8 May 3, 2024

This is a critical SQL injection vulnerability in Voltronic Power ViewPower Pro that allows unauthenticated remote attackers to execute arbitrary code. Attackers can exploit the selectEventConfig meth...

CVE-2023-51581

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Voltronic Power ViewPower installations without authentication. The exposed dangerous method in the MacMonitorConsole class enab...

CVE-2023-51574

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows remote attackers to bypass authentication on Voltronic Power ViewPower systems without requiring credentials. The exposed updateManagerPassword method enables complete authen...

CVE-2023-51576

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Voltronic Power ViewPower systems. The flaw exists in the RMI interface on TCP port 51099...

CVE-2023-51572

CRITICAL CVSS 9.8 Apr 1, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary system commands on Voltronic Power ViewPower Pro installations. Attackers can exploit a command injection flaw in the ge...

CVE-2023-51570

CRITICAL CVSS 9.8 Apr 1, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Voltronic Power ViewPower Pro installations. The flaw exists in the RMI interface on TCP ...

CVE-2023-51588

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows local attackers with initial low-privileged access to escalate to SYSTEM privileges on Voltronic Power ViewPower Pro installations. Attackers exploit hard-coded MySQL databas...

CVE-2023-51585

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Voltronic Power ViewPower Pro systems by injecting malicious commands into the shutdown operation. Attackers can gain code execu...

CVE-2023-51578

HIGH CVSS 7.5 May 3, 2024

This vulnerability allows remote attackers to cause denial-of-service conditions on Voltronic Power ViewPower systems without authentication. The exposed dangerous method in the MonitorConsole class c...