PT-2022-24213 · Unknown · Upsmon Pro

Michael Heinzl

·

Published

2022-11-10

·

Updated

2022-11-15

·

CVE-2022-38119

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UPSMON Pro (affected versions not specified)
Description The UPSMON Pro login function has insufficient authentication, allowing an unauthenticated remote attacker to bypass authentication and gain administrator privileges to access, control the system, or disrupt the service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-38119

Affected Products

Upsmon Pro