Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25133

Опубликовано: 24 апр. 2023
Источник: nvd
CVSS3: 9.1
CVSS3: 9.8
EPSS Низкий

Описание

Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to execute operation system commands via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:linux:*:*
Версия до 4.8.6 (включая)
cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:macos:*:*
Версия до 4.8.6 (включая)
cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:virtual_machine:*:*
Версия до 4.8.6 (включая)
cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:*
Версия до 4.8.6 (включая)

EPSS

Процентиль: 52%
0.00291
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-269
CWE-269

Связанные уязвимости

CVSS3: 9.1
github
почти 3 года назад

Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to execute operation system commands via unspecified vectors.

EPSS

Процентиль: 52%
0.00291
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-269
CWE-269