CVE-2022-31491
CRITICALVoltronic Power ViewPower <1.04-24215, ViewPower Pro <2.0-22165, Po...
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-31491. PoCs published by ready2disclose.
AI-analyzed exploit summary This repository contains a writeup for CVE-2022-31491, describing an exposed unsafe functionality vulnerability in Voltronic Viewpower/Pro UPS management software. The vulnerability allows unauthenticated remote code execution (RCE) due to improper exposure of a critical function over the network.
Description
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code immediately regardless of any managed UPS state or presence.
Exploits (1)
This repository contains a writeup for CVE-2022-31491, describing an exposed unsafe functionality vulnerability in Voltronic Viewpower/Pro UPS management software. The vulnerability allows unauthenticated remote code execution (RCE) due to improper exposure of a critical function over the network.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H