Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
CriticalPublic exploit

Unauthenticated RCE in Voltronic Power ViewPower / ViewPower Pro / PowerShield Netguard

IdentifiersCVE-2022-31491CWE-20

CVE-2022-31491 is a critical remote code execution vulnerability affecting Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292. According to the provided content, the flaw is reachable through an unspecified web interface related to detection of a managed UPS shutting down. The issue allows a remote attacker to run arbitrary code, and exploitation does not require authentication. The content further states that exploitation is possible immediately regardless of whether a managed UPS is present or whether any UPS shutdown condition actually exists, indicating that the vulnerable web-exposed functionality can be triggered independently of real device state. Based on the supporting context, the weakness is most consistent with improper input validation in the affected web interface.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows unauthenticated remote arbitrary code execution on the host running the affected UPS monitoring/management software. In operational environments, this can enable full compromise of the management console, manipulation of UPS-related configuration and shutdown logic, disruption of power-management workflows, and use of the compromised system as a foothold for further intrusion. Because these products are used to monitor and control UPS infrastructure, compromise can create high-impact disruption risk in enterprise and ICS/OT environments.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, remove or strictly limit network exposure of the affected web interface, especially from the internet and untrusted networks. Place the management application behind network segmentation and firewall rules, restrict access to dedicated administrative hosts or VPN-only paths, disable or isolate unnecessary web access where operationally feasible, and monitor for unexpected changes to UPS configuration or shutdown logic. Given the unauthenticated nature of the flaw, exposure reduction is critical until remediation is complete.

Remediation

Patch, then assume compromise.

Upgrade to a fixed release: ViewPower newer than 1.04-24215, ViewPower Pro newer than 2.0-22165, and PowerShield Netguard 1.04-23292 or later, as applicable. Apply vendor-provided updates on all systems running the affected UPS monitoring software, verify that exposed web interfaces are updated, and review UPS shutdown/configuration settings for unauthorized changes after patching.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.