CRITICAL🇵🇱 Wersja polska

CVE-2023-3266

CVSS 9.8v3.1pub. 2023-08-14upd. 2024-11-21

A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator by selecting LDAP authentication from a hidden HTML combo box. Successful exploitation of this vulnerability also requires the attacker to know at least one username on the device, but any password will authenticate successfully.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cyberpower Powerpanel Server

    APP
    Cyberpower
    < 2.6.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-3265CRITICAL9.8PL ✓same product

Authentication bypass w CyberPower PowerPanel Enterprise poprzez meta-znaki

CVE-2023-3267CRITICAL9.1PL ✓same product

CyberPower PowerPanel Server — command injection w polu nazwy użytkownika

CVE-2023-3260HIGH7.2same product

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection v...

CVE-2023-3261HIGH7.5same product

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerabi...

CVE-2023-3264MEDIUM6.7same product

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all ...