Record summary

CVE-2024-32735 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 2.8.3affected

Default status: unaffected

VulnCheck, CVE ListBefore 2.8.3affected

Nuclei templates

1
ProjectDiscoveryCRITICALCyberPower - Missing AuthenticationCVSS 9.8

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3.

Impact

An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-306
AuthorsDhiyaneshDK
Template tagscvecve2024cyberpowerauth-bupassvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: html:"<title>PDNU</title>"

Source: ProjectDiscovery

References

3