CVE-2024-32735
CyberPower PowerPanel Enterprise Missing Authentication
Record summary
CVE-2024-32735 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
CyberPower PowerPanel EnterpriseBrowse CyberPower / CyberPower PowerPanel EnterpriseDefault status: unaffected | CVE List | Before 2.8.3 | affected |
PowerPanel EnterpriseBrowse CyberPower / PowerPanel EnterpriseDefault status: unaffected | VulnCheck, CVE List | Before 2.8.3 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALCyberPower - Missing AuthenticationCVSS 9.8
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3.
Impact
An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Source: ProjectDiscovery