CRITICAL🇵🇱 Wersja polska

CVE-2024-32735

CVSS 9.8v3.1pub. 2024-05-14upd. 2025-10-23

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

🤖 AI Analysis
How it works

The vulnerability results from the lack of an authentication mechanism (CWE-306) for specific tools and endpoints of the PDNU REST API in the PowerPanel Enterprise application. A remote attacker without any credentials can directly send requests to these APIs over the network, bypassing any access controls. The lack of login requirement means there is no barrier to entry for a potential attacker.

Impact

An unauthenticated remote attacker can gain full access to application functions, which may lead to violations of confidentiality, integrity, and availability of the PowerPanel Enterprise system, and consequently to the takeover of management of connected UPS devices.

Mitigation & patch

CyberPower PowerPanel Enterprise must be updated to version 2.8.3 or newer. Details are available in the manufacturer's release notes and in the Tenable TRA-2024-14 report.

Who is affected

CyberPower PowerPanel Enterprise in versions prior to v2.8.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cyberpower Powerpanel

    APP
    Cyberpower
    < 2.8.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-33625CRITICAL9.8PL ✓same product

CyberPower PowerPanel: zakodowany klucz JWT umożliwia ominięcie uwierzytelnienia

CVE-2024-34025CRITICAL9.8PL ✓same product

CyberPower PowerPanel Business — zakodowane dane uwierzytelniające

CVE-2024-32047CRITICAL9.8PL ✓same product

CyberPower PowerPanel — zakodowane na stałe dane uwierzytelniające w kodzie produkcyjnym

CVE-2024-32053CRITICAL9.8PL ✓same product

CyberPower PowerPanel — zakodowane na stałe dane uwierzytelniające (hard-coded credentials)

CVE-2023-25133CRITICAL9.1PL ✓same product

RCE w CyberPower PowerPanel Business — nieprawidłowe zarządzanie uprawnieniami