nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-32042 CVE-2024-32042
MEDIUM
CyberPower PowerPanel business Storing Passwords in a Recoverable Format
Record summary
CVE-2024-32042 has a selected CVSS score of 4.9 (medium).
Description
The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be recovered.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 24, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PowerPanel businessBrowse CyberPower / PowerPanel businessDefault status: unaffected, affected | CVE List | Before 4.9.0 | affected |
References
3cisa.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01 cyberpower.com
https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows