CVE-2024-32047

CRITICAL

CyberPower PowerPanel - Info Disclosure

Title source: llm
STIX 2.1

Description

Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.

Scores

CVSS v3 9.8
EPSS 0.0021
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-489
Status published
Products (1)
cyberpower/powerpanel < 4.9.0
Published May 15, 2024
Tracked Since Feb 18, 2026