CVE-2023-51590 is a critical unrestricted file upload vulnerability in Voltronic Power ViewPower Pro, allowing unauthenticated remote attackers to execute arbitrary code. With a CVSS score of 9.8, this flaw enables attackers to upload malicious files due to insufficient input validation, leading to code execution in the context of LOCAL SERVICE. While no public exploits or active exploitation are currently reported, its high severity and ease of exploitation warrant immediate attention. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0-22165CPE matchmatch criteria | cpe:2.3:a:voltronicpower:viewpower:2.0-22165:*:*:*:pro:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.