CVE-2022-38119

UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6678-e9fbe-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:upspowercom:upsmon_pro:2.57:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-11-10 15:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-38119

Mitre link : CVE-2022-38119

CVE.ORG link : CVE-2022-38119


JSON object : View

Products Affected

upspowercom

  • upsmon_pro
CWE
CWE-287

Improper Authentication