CVE-2023-3265

CVSS V2 None CVSS V3 None
Description
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.
Overview
  • CVE ID
  • CVE-2023-3265
  • Assigner
  • trellixpsirt@trellix.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-08-14T05:15:09
  • Last Modified Date
  • 2023-08-22T16:20:24
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:cyberpower:powerpanel_server:*:*:*:*:enterprise:*:*:* 1 OR 2.6.9
History
Created Old Value New Value Data Type Notes
2023-09-06 03:41:25 Added to TrackCVE
2023-09-06 03:41:27 Weakness Enumeration new