Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-33175

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

CVE

(pic 2/7) R U A HACKER NINJA?

Related news

Security researcher receives legal threat over patched Powertek data center vulnerabilities

Vendor threatened legal action following disclosure and fixes being issued, bug hunter claims

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907