Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 4.1.0
affected
Default status
unaffected
Any version before 4.1.0
affected
Description
By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthorized users to access and manipulate monitoring and control functions.
Problem types
Product status
Any version before 4.1.0
Any version before 4.1.0
Credits
Anthony Rose and Jacob Krasnov of BC Security reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-219-05