CVE-2023-3267
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Aug 14, 2023
Updated: Aug 22, 2023
CWE ID 670
Summary
CVE-2023-3267 is a serious vulnerability affecting the CyberPower PowerPanel Enterprise server. When users add a new remote backup location, they can input arbitrary OS commands into the username field without proper sanitization. These commands are then passed to CMD, which runs as NT/Authority System. This issue allows authenticated attackers to execute arbitrary code with system-level access, posing a significant risk to the affected server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Vyperlang Vyper