go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

POWERCOM CO., LTD. UPSMON PRO - Broken Authentication

TVN ID TVN-202208004
CVE ID CVE-2022-38119
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products POWERCOM CO., LTD. UPSMON PRO version 2.57
Description UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt service.
Solution Contact tech support from POWERCOM CO., LTD.
Credit Michael Heinzl
Public Date 2022-11-10
Top