Vulnerabilities > Upspowercom

DATE CVE VULNERABILITY TITLE RISK
2022-11-10 CVE-2022-38119 Improper Authentication vulnerability in Upspowercom Upsmon PRO 2.57
UPSMON Pro login function has insufficient authentication.
network
low complexity
upspowercom CWE-287
critical
9.8
2022-11-10 CVE-2022-38120 Path Traversal vulnerability in Upspowercom Upsmon PRO 2.57
UPSMON PRO’s has a path traversal vulnerability.
network
low complexity
upspowercom CWE-22
6.5
2022-11-10 CVE-2022-38121 Insufficiently Protected Credentials vulnerability in Upspowercom Upsmon PRO 2.57
UPSMON PRO configuration file stores user password in plaintext under public user directory.
network
low complexity
upspowercom CWE-522
6.5
2022-11-10 CVE-2022-38122 Cleartext Transmission of Sensitive Information vulnerability in Upspowercom Upsmon PRO 2.57
UPSMON PRO transmits sensitive data in cleartext over HTTP protocol.
network
low complexity
upspowercom CWE-319
7.5