CVE-2022-43110
BaseFortify
Publication date: 2025-08-22
Last updated on: 2025-08-25
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| voltronic | netguard | * |
| voltronic | viewpower | * |
| voltronic | powershield | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-425 | The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows an unauthenticated remote attacker to access and configure the system via an unspecified web interface. The attacker can change the web interface admin password, view and modify system configurations, enumerate connected UPS devices, and shut down those UPS devices. Additionally, the attacker can configure operating system commands that execute when the system detects a connected UPS shutting down.
How can this vulnerability impact me? :
This vulnerability can have serious impacts including unauthorized control over the system managing UPS devices. An attacker could disrupt power management by shutting down connected UPS devices, potentially causing downtime or damage to connected equipment. They could also change administrative credentials and system configurations, leading to loss of control and further exploitation.