PT-2023-8156 · Voltronic Power · Voltronic Power Viewpower

Published

2023-12-20

·

Updated

2025-07-09

·

CVE-2023-51574

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Voltronic Power ViewPower (affected versions not specified)
Description This issue allows remote attackers to bypass authentication on affected installations of Voltronic Power ViewPower. The specific flaw exists within the updateManagerPassword method, which is exposed and can be leveraged by an attacker to bypass authentication on the system. No authentication is required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the updateManagerPassword method until a patch is available. Restrict access to the affected system to minimize the risk of exploitation. Avoid using the updateManagerPassword method in the affected API endpoint until the issue is resolved.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-00140
CVE-2023-51574
ZDI-23-1880

Affected Products

Voltronic Power Viewpower