PT-2024-4518 · Cyberpower · Cyberpower Powerpanel Enterprise

Published

2024-05-09

·

Updated

2024-07-03

·

CVE-2024-32735

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CyberPower PowerPanel Enterprise versions prior to 2.8.3
Description: The issue is related to missing authentication for certain utilities in CyberPower PowerPanel Enterprise, allowing an unauthenticated remote attacker to access the PDNU REST APIs. This may result in the compromise of the application. An attacker can exploit this issue to gain unauthorized access to the application through the REST API.
Recommendations: For versions prior to 2.8.3, update to version 2.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the PDNU REST APIs until a patch is available.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-05022
CVE-2024-32735

Affected Products

Cyberpower Powerpanel Enterprise