PT-2024-3235 · Cyberpower · Cyberpower Powerpanel

Published

2024-05-02

·

Updated

2024-05-16

·

CVE-2024-32047

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberPower PowerPanel (affected versions not specified)
Description The issue is related to hard-coded credentials for the test server found in the production code, which could allow an attacker to gain access to the testing or production server. The vulnerability is associated with insufficient protection of service data during the implementation of debug code, potentially enabling a remote attacker to obtain unauthorized access to credentials and elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-03464
CVE-2024-32047

Affected Products

Cyberpower Powerpanel