An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.
The vulnerability results from the lack of an authentication mechanism (CWE-306) for specific tools and endpoints of the PDNU REST API in the PowerPanel Enterprise application. A remote attacker without any credentials can directly send requests to these APIs over the network, bypassing any access controls. The lack of login requirement means there is no barrier to entry for a potential attacker.
An unauthenticated remote attacker can gain full access to application functions, which may lead to violations of confidentiality, integrity, and availability of the PowerPanel Enterprise system, and consequently to the takeover of management of connected UPS devices.
CyberPower PowerPanel Enterprise must be updated to version 2.8.3 or newer. Details are available in the manufacturer's release notes and in the Tenable TRA-2024-14 report.
CyberPower PowerPanel Enterprise in versions prior to v2.8.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCyberpower Powerpanel
APPCyberpower< 2.8.3
Related vulnerabilities
CyberPower PowerPanel: zakodowany klucz JWT umożliwia ominięcie uwierzytelnienia
CyberPower PowerPanel Business — zakodowane dane uwierzytelniające
CyberPower PowerPanel — zakodowane na stałe dane uwierzytelniające w kodzie produkcyjnym
CyberPower PowerPanel — zakodowane na stałe dane uwierzytelniające (hard-coded credentials)
RCE w CyberPower PowerPanel Business — nieprawidłowe zarządzanie uprawnieniami