Vulnerability record · CVE-2023-51573 · published 1 April 2024
CVE-2023-51573: Voltronic Power ViewPower Pro updateManagerPassword auth bypass
Voltronicpower · Viewpower
ViewPower Pro exposes a dangerous function, updateManagerPassword, that lets a remote attacker bypass authentication. Because the flaw is reachable without credentials and the CVSS vector shows no user interaction, any network-reachable instance is at risk. The record does not list affected version ranges, so defenders must confirm exposure against their own deployment.
Description
Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this vulnerability. The specific flaw exists within the updateManagerPassword function. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21203.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote authentication bypass with CVSS 9.8 and very high EPSS, though no KEV listing or confirmed exploitation is documented.
What it is
ViewPower Pro exposes a dangerous function, updateManagerPassword, that lets a remote attacker bypass authentication. Because the flaw is reachable without credentials and the CVSS vector shows no user interaction, any network-reachable instance is at risk. The record does not list affected version ranges, so defenders must confirm exposure against their own deployment.
Impact
An attacker gains full unauthenticated access to the system, with high confidentiality, integrity and availability impact per the CVSS vector. In practice this means control over the management interface and the data and power-management functions it governs.
Attack surface
Reached over the network via the exposed updateManagerPassword function; the CVSS vector is AV:N/PR:N/UI:N, so no authentication and no user interaction are required. The description does not specify the exact port or endpoint, so the reachable service must be identified from the deployment.
Exploitation
Not listed in CISA KEV and no public exploit reference is given beyond the ZDI advisory, but EPSS is 0.457 (98.7th percentile), indicating elevated likelihood of exploitation activity. Treat as high-risk despite the absence of confirmed in-the-wild reporting.
What to do
- Apply the vendor fix for ViewPower Pro as soon as Voltronic Power publishes it; the record does not name a patched version, so confirm with the vendor.
- Until patched, remove ViewPower Pro management interfaces from untrusted networks and restrict access to a management VLAN or VPN.
- Block or filter external access to the service port and monitor for unexpected inbound connections to it.
- Audit and rotate any credentials or configuration reachable through the management interface, since authentication can be bypassed.
- If the product cannot be isolated or patched, consider taking the affected instance offline.
Detection
- Monitor for unauthenticated or anomalous requests to the updateManagerPassword function or related management endpoints.
- Alert on successful management logins or configuration changes from unexpected source IPs or at unusual times.
- Baseline normal ViewPower Pro network traffic and flag new external connections to its service ports.
- Review application and system logs for authentication bypass indicators or unexpected administrative actions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-23-1879/ | Third Party Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1879/ | Third Party Advisory |
Track CVE-2023-51573 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-51573), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.