Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-11322
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0.
An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unavailable.
0
Attacker Value
Unknown
CVE-2024-34025
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
CyberPower PowerPanel business application code contains a hard-coded set of authentication
credentials. This could result in an attacker bypassing authentication
and gaining administrator privileges.
0
Attacker Value
Unknown
CVE-2024-33625
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
CyberPower PowerPanel business
application code contains a hard-coded JWT signing key. This could
result in an attacker forging JWT tokens to bypass authentication.
0
Attacker Value
Unknown
CVE-2024-33615
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
A specially crafted Zip file containing path traversal characters can be
imported to the
CyberPower PowerPanel
server, which allows file writing to the server outside
the intended scope, and could allow an attacker to achieve remote code
execution.
0
Attacker Value
Unknown
CVE-2024-32053
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
Hard-coded credentials are used by the
CyberPower PowerPanel
platform to authenticate to the
database, other services, and the cloud. This could result in an
attacker gaining access to services with the privileges of a Powerpanel
business application.
0
Attacker Value
Unknown
CVE-2024-32047
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
Hard-coded credentials for the
CyberPower PowerPanel test server can be found in the
production code. This might result in an attacker gaining access to the
testing or production server.
0
Attacker Value
Unknown
CVE-2024-32042
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
The key used to encrypt passwords stored in the database can be found in
the
CyberPower PowerPanel
application code, allowing the passwords to be recovered.
0
Attacker Value
Unknown
CVE-2024-31856
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
An attacker with certain MQTT permissions can create malicious messages
to all CyberPower PowerPanel devices. This could result in an attacker injecting
SQL syntax, writing arbitrary files to the system, and executing remote
code.
0
Attacker Value
Unknown
CVE-2024-31410
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
The devices which CyberPower PowerPanel manages use identical certificates based on a
hard-coded cryptographic key. This can allow an attacker to impersonate
any client in the system and send malicious data.
0
Attacker Value
Unknown
CVE-2024-31409
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
Certain MQTT wildcards are not blocked on the
CyberPower PowerPanel
system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
0