PT-2023-23945 · Cyberpower · Cyberpower Powerpanel Enterprise

Philippe Laulheret

·

Published

2023-08-12

·

Updated

2023-08-22

·

CVE-2023-3267

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberPower PowerPanel Enterprise (affected versions not specified)
Description The issue allows an authenticated user to pass arbitrary OS commands through the username field when adding a remote backup location. This field is passed without sanitization into CMD running as NT/Authority System, enabling an authenticated attacker to execute arbitrary code with system-level access to the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-3267

Affected Products

Cyberpower Powerpanel Enterprise