Lucene search

K
vulnrichmentIcscertVULNRICHMENT:CVE-2024-32047
HistoryMay 15, 2024 - 7:36 p.m.

CVE-2024-32047 CyberPower PowerPanel business Active Debug Code

2024-05-1519:36:41
CWE-489
icscert
github.com
1
cve-2024-32047
cyberpower powerpanel
hard-coded credentials
test server
production server
attacker access

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Hard-coded credentials for the
CyberPower PowerPanel test server can be found in the
production code. This might result in an attacker gaining access to the
testing or production server.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:cyberpower:powerpanel_business:*:*:*:*:*:*:*:*"
    ],
    "vendor": "cyberpower",
    "product": "powerpanel_business",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "4.9.0",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-32047