S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-28343 Scanner

Detects 'Command Injection' vulnerability in Altenergy Power Control Software affects v. C1.2.5.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-28343
9.8
CVSS

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Altenergy Power Control Software C1.2.5 is an advanced power management system designed to control and monitor the energy consumption of various devices within a facility. This software is used in various industries such as hospitals, data centers, and industrial plants to monitor and optimize their energy usage, thus reducing costs and enhancing sustainability efforts. The software is highly customizable, and users can configure it to meet their specific needs, making it a cost-efficient solution for energy management.

CVE-2023-28343 is a vulnerability detected in Altenergy Power Control Software C1.2.5. The vulnerability arises from shell metacharacters found in the timezone parameter of index.php/management/set_timezone. Hackers can exploit this weakness and inject OS commands into the system. This vulnerability can allow an attacker to execute arbitrary code or commands on the system, giving them unauthorized access to sensitive data and other resources.

When this vulnerability is exploited, it can lead to serious consequences. Attackers can gain full control of the affected system, enabling them to steal sensitive data, disrupt operations, or even launch other attacks on the network. Moreover, the vulnerability can lead to a complete system compromise, making it difficult or impossible to recover the affected system from the attack.

Thanks to the pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their digital assets. The platform provides real-time security alerts, detailed vulnerability reports, and personalized recommendations to help users protect their systems against threats. With s4e.io, users can stay ahead of potential vulnerabilities and safeguard their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Ensure that the software is always up to date with the latest security patches and updates.
  • Implement proper access control measures to limit access to sensitive resources.
  • Deploy effective intrusion detection and prevention systems to detect and block any suspicious activities on the system.
  • Conduct regular security audits and vulnerability assessments to identify and mitigate any weak points in the system.
  • Train employees on security best practices to ensure they understand the risks and know how to respond appropriately to threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.