Upspowercom
Upspowercom Upsmon PRO: vulnerabilidades y CVE
Upspowercom Upsmon PRO tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-38122 | Alta (7.5) | 0.54% | — | 10 nov 2022 | UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data. |
| CVE-2022-38121 | Media (6.5) | 3.5% | — | 10 nov 2022 | UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access all users‘ and administrators' account names and passwords via this… |
| CVE-2022-38120 | Media (6.5) | 5.8% | — | 10 nov 2022 | UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files. |
| CVE-2022-38119 | Crítica (9.8) | 1.1% | — | 10 nov 2022 | UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt… |