Powertek PDU Firmware information disclosure | CVE-2022-33174
NAME
Powertek PDU Firmware information disclosure
- Platforms Affected:
Powertek PDU firmware 3.30.17 - Risk Level:
8.8 - Exploitability:
Unproven - Consequences:
Obtain Information
DESCRIPTION
Powertek PDU Firmware could allow a remote attacker to obtain sensitive information, caused by an authorization bypass flaw in the web interface. By sending a specially-crafted HTTP packet to the data retrieval interface, an attacker could exploit this vulnerability to obtain protected sys.passwd and sys.su.name fields information in cleartext, and use this information to launch further attacks against the affected system.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of Powertek firmware (3.30.30 or later), available from the Powertek Web site. See References.
- Reference Link:
https://gynvael.coldwind.pl/?lang=en&id=748 - Reference Link:
https://www.powertekpdus.com/
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.