HTTP: Voltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload

This signature detects attempts to exploit a known vulnerability against Voltronic Power ViewPower Pro. A successful attack can lead to arbitrary code execution.

Extended Description

Voltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UpLoadAction class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE. Was ZDI-CAN-22080.

Short Name
HTTP:CTS:VOLTRNC-PW-FL-UPLOAD
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2023-51590 File Power Pro Unrestricted UpLoadAction Upload ViewPower Voltronic
Release Date
02/20/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3702
False Positive
Rarely

Found a potential security threat?