CVE-2022-38120
MEDIUMPOWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
Title source: metasploitExploitation Summary
EIP tracks 1 public exploit for CVE-2022-38120.
PoCs published by Michael Heinzl, including Metasploit module auxiliary/gather/upsmon_traversal.
AI-analyzed exploit summary This Metasploit module exploits a path traversal vulnerability (CVE-2022-38120) in POWERCOM UPSMON PRO to retrieve arbitrary files, including the configuration file containing credentials (CVE-2022-38121). It sends a crafted HTTP GET request with traversal sequences to access sensitive files and parses credentials from the retrieved data.
Description
UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files.
Exploits (1)
This Metasploit module exploits a path traversal vulnerability (CVE-2022-38120) in POWERCOM UPSMON PRO to retrieve arbitrary files, including the configuration file containing credentials (CVE-2022-38121). It sends a crafted HTTP GET request with traversal sequences to access sensitive files and parses credentials from the retrieved data.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N