Upspowercom develops power-management and monitoring software centered on its UPSMon Pro product, which serves as a control point for uninterruptible power supply infrastructure. The recurring vulnerability pattern across this vendor's disclosures centers on credential and authentication handling, including cleartext transmission of sensitive data, improper authentication logic, path traversal, and insufficiently protected credential storage—weaknesses typical of legacy or tightly scoped administrative tools where security hardening may not have been a primary design focus.
The number and severity of CVEs published that impact products developed by Upspowercom over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38120MEDIUM UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system f | Nov 10, 2022 | 6.5 | 34 | NO | YES |
CVE-2022-38121MEDIUM UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access all users‘ and administrators' | Nov 10, 2022 | 6.5 | 32 | NO | YES |
CVE-2022-38119CRITICAL UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privileg | Nov 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-38122HIGH UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data. | Nov 10, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Upspowercom.
Media articles that mention a CVE ID that affects a product developed by Upspowercom — matched by CVE ID, not by vendor name.