ZeroHour

CVE-2022-38119

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt service.

Vendors
upspowercom
Products
upsmon pro
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.