Required CVE Record Information
Description
Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getModbusPassword method. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-22073.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
7.5 | HIGH | 3.0 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
References 1 Total
- zerodayinitiative.com: ZDI-23-1892 x_research-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 1 Total
- zerodayinitiative.com: ZDI-23-1892 x_research-advisoryx_transferred