Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
CriticalPublic exploit

Unauthenticated Remote Configuration in Voltronic Power ViewPower / PowerShield Netguard

IdentifiersCVE-2022-43110CWE-306· Missing Authentication for…

CVE-2022-43110 affects Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292. The products expose an unspecified web interface that permits remote system configuration without authentication. According to the provided description, an unauthenticated remote attacker can change the web interface administrator password, view and modify system configuration, enumerate connected UPS devices, and issue shutdown actions to connected UPS devices. The flaw also allows modification of the operating system command configuration used when the software detects a connected UPS shutdown event, creating a high-risk path for abuse of UPS management and shutdown logic. Based on the available information, the core issue is missing authentication for critical administrative functionality exposed over the web interface.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows a remote unauthenticated attacker to take administrative control over the UPS management application configuration. This can result in unauthorized password changes, tampering with monitoring and shutdown settings, enumeration of attached UPS assets, and forced shutdown of connected UPS devices, creating significant availability and operational disruption risk in environments relying on these systems. Because the attacker can also configure operating system commands associated with UPS shutdown events, exploitation may additionally enable execution of attacker-selected system actions in the context of the affected host when the relevant event is triggered, further increasing the potential impact on the managed environment.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, remove or strictly limit network exposure of the web management interface, especially from untrusted or internet-reachable networks. Place the application behind network segmentation and ACLs, restrict access to dedicated management hosts or VPN-only administrative paths, and monitor for unauthorized configuration changes, password resets, UPS enumeration, and shutdown actions. Review and disable or tightly control any operating system command execution features associated with UPS events where operationally feasible. Continuous logging and alerting around administrative web actions should be enabled to detect abuse.

Remediation

Patch, then assume compromise.

Upgrade Voltronic Power ViewPower to a version newer than 1.04-21353 and PowerShield Netguard to version 1.04-23292 or later, as indicated by the affected-version information. Validate that the exposed web interface no longer permits unauthenticated access to administrative functions after upgrade. Review all application settings for unauthorized changes, including administrator credentials, UPS shutdown policies, and any configured operating system commands tied to UPS events. If compromise is suspected, rotate credentials, restore trusted configuration, and inspect the host for malicious command configuration or follow-on activity.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.