Vulnerability Details CVE-2022-38121
UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access all users‘ and administrators' account names and passwords via this unprotected configuration file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.391
EPSS Ranking 97.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2022-38121
-
cpe:2.3:a:upspowercom:upsmon_pro:2.57