« Volver al listado

CVE-2023-51575

Estado: AnalizadaCrítica (9.8)—

Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the MonitorConsole class. The issue results from an exposed dangerous method. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22011.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-51575",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-51575",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-03T19:53:30.369307Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "zdi-disclosures@trendmicro.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "zdi-disclosures@trendmicro.com",
      "affectedData": [
        {
          "vendor": "Voltronic Power",
          "product": "ViewPower",
          "versions": [
            {
              "status": "affected",
              "version": "1.04.21353"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:voltronicpower:viewpower:1.04.21353:*:*:*:*:*:*:*"
          ],
          "vendor": "voltronicpower",
          "product": "viewpower",
          "versions": [
            {
              "status": "affected",
              "version": "1.04.21353"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-03T03:16:16.747",
  "references": [
    {
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-1881/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "zdi-disclosures@trendmicro.com"
    },
    {
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-1881/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "zdi-disclosures@trendmicro.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-749"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the MonitorConsole class. The issue results from an exposed dangerous method. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22011."
    },
    {
      "lang": "es",
      "value": "Voltronic Power ViewPower MonitorConsole expuso una vulnerabilidad de ejecución remota de código de método peligroso. Esta vulnerabilidad permite a atacantes remotos ejecutar código arbitrario en las instalaciones afectadas de Voltronic Power ViewPower. No se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe dentro de la clase MonitorConsole. El problema se debe a un método peligroso expuesto. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto del usuario actual. Fue ZDI-CAN-22011."
    }
  ],
  "lastModified": "2026-06-17T06:41:14.750",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:voltronicpower:viewpower:1.04.21353:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CE4A520-86B5-4AE3-AD0E-7744328090E4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "zdi-disclosures@trendmicro.com"
}