7.7

CVE-2024-31410

The devices which CyberPower PowerPanel manages use identical certificates based on a 
hard-coded cryptographic key. This can allow an attacker to impersonate 
any client in the system and send malicious data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CyberpowerPowerpanel SwEditionbusiness SwPlatformwindows Version <= 4.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.315
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
ics-cert@hq.dhs.gov 7.7 3.1 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
CWE-321 Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.