CVE-2022-38119 is a critical authentication bypass vulnerability in the UPSMON Pro login function, affecting upspowercom upsmon_pro. An unauthenticated remote attacker can exploit this flaw to gain administrator privileges, enabling full access, control, or disruption of the system. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 93/100, the vulnerability is easily exploitable over the network with no user interaction. While there are no known public exploits (Metasploit, Nuclei, ExploitDB) or evidence of active exploitation (KEV, Hot List), it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.57CPE matchmatch criteria | cpe:2.3:a:upspowercom:upsmon_pro:2.57:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.