Cyberpower
Cyberpower Powerpanel Server: vulnerabilidades y CVE
Cyberpower Powerpanel Server tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-3267 | Alta (8.8) | 1.8% | — | 14 ago 2023 | When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An… |
| CVE-2023-3266 | Crítica (9.8) | 0.88% | — | 14 ago 2023 | A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage… |
| CVE-2023-3265 | Crítica (9.8) | 1.6% | — | 14 ago 2023 | An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by… |
| CVE-2023-3264 | Crítica (9.8) | 0.47% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating… |
| CVE-2023-3261 | Alta (7.2) | 0.78% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected… |
| CVE-2023-3260 | Alta (8.8) | 1.3% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute… |