← Vulnerability feed

Vulnerability record · CVE-2023-51573 · published 1 April 2024

CVE-2023-51573: Voltronic Power ViewPower Pro updateManagerPassword auth bypass

Voltronicpower · Viewpower

ViewPower Pro exposes a dangerous function, updateManagerPassword, that lets a remote attacker bypass authentication. Because the flaw is reachable without credentials and the CVSS vector shows no user interaction, any network-reachable instance is at risk. The record does not list affected version ranges, so defenders must confirm exposure against their own deployment.

9.8 CVSS 3.0 Critical EPSS 46% · top 1.2% CWE-749 · CWE-749
9.8CVSS 3.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The specific flaw exists within the updateManagerPassword function. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21203.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityUnauthenticated remote authentication bypass with CVSS 9.8 and very high EPSS, though no KEV listing or confirmed exploitation is documented.

What it is

ViewPower Pro exposes a dangerous function, updateManagerPassword, that lets a remote attacker bypass authentication. Because the flaw is reachable without credentials and the CVSS vector shows no user interaction, any network-reachable instance is at risk. The record does not list affected version ranges, so defenders must confirm exposure against their own deployment.

Impact

An attacker gains full unauthenticated access to the system, with high confidentiality, integrity and availability impact per the CVSS vector. In practice this means control over the management interface and the data and power-management functions it governs.

Attack surface

Reached over the network via the exposed updateManagerPassword function; the CVSS vector is AV:N/PR:N/UI:N, so no authentication and no user interaction are required. The description does not specify the exact port or endpoint, so the reachable service must be identified from the deployment.

Exploitation

Not listed in CISA KEV and no public exploit reference is given beyond the ZDI advisory, but EPSS is 0.457 (98.7th percentile), indicating elevated likelihood of exploitation activity. Treat as high-risk despite the absence of confirmed in-the-wild reporting.

What to do

  • Apply the vendor fix for ViewPower Pro as soon as Voltronic Power publishes it; the record does not name a patched version, so confirm with the vendor.
  • Until patched, remove ViewPower Pro management interfaces from untrusted networks and restrict access to a management VLAN or VPN.
  • Block or filter external access to the service port and monitor for unexpected inbound connections to it.
  • Audit and rotate any credentials or configuration reachable through the management interface, since authentication can be bypassed.
  • If the product cannot be isolated or patched, consider taking the affected instance offline.

Detection

  • Monitor for unauthenticated or anomalous requests to the updateManagerPassword function or related management endpoints.
  • Alert on successful management logins or configuration changes from unexpected source IPs or at unusual times.
  • Baseline normal ViewPower Pro network traffic and flag new external connections to its service ports.
  • Review application and system logs for authentication bypass indicators or unexpected administrative actions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-51573 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-51595Voltronic Power ViewPower Pro SQL Injection Enables Remote Code ExecutionViewPower Pro fails to validate user-supplied input in the selectDeviceListBy method before building SQL queries, allowing SQL injection. Because the…EPSS 48%analysed9.8CVE-2023-51590Voltronicpower viewpower unrestricted file upload vulnerabilityVoltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…EPSS 1.5%9.8CVE-2023-51593Voltronicpower viewpower expression language injection vulnerabilityVoltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…EPSS 1.6%9.8CVE-2023-51582Voltronicpower viewpower vulnerabilityVoltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 1.5%9.8CVE-2023-51583Voltronicpower viewpower vulnerabilityVoltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…EPSS 1.5%9.8CVE-2023-51586Voltronicpower viewpower sql injection vulnerabilityVoltronic Power ViewPower Pro selectEventConfig SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec…EPSS 1.3%9.8CVE-2023-51581Voltronicpower viewpower vulnerabilityVoltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers …EPSS 1.5%9.8CVE-2023-51574Voltronicpower viewpower vulnerabilityVoltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerability. This vulnerability allows remote attack…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2023-51573), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.