CVE-2022-38119

UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:upspowercom:upsmon_pro:2.57:*:*:*:*:*:*:*

History

21 Nov 2024, 07:15

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-6678-e9fbe-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-6678-e9fbe-1.html - Third Party Advisory

Information

Published : 2022-11-10 15:15

Updated : 2024-11-21 07:15


NVD link : CVE-2022-38119

Mitre link : CVE-2022-38119

CVE.ORG link : CVE-2022-38119


JSON object : View

Products Affected

upspowercom

  • upsmon_pro
CWE
CWE-287

Improper Authentication