← Zuruck zu CVEs
CVE-2024-32053
CRITICAL9.8
Beschreibung
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht5/15/2024
Zuletzt geandert7/30/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
cyberpower:powerpanel
Schwachen (CWE)
CWE-798
Referenzen
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01(ics-cert@hq.dhs.gov)
https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads(ics-cert@hq.dhs.gov)
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01(af854a3a-2127-422b-91ae-364da2661108)
https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.