9.8

CVE-2024-32053

CyberPower PowerPanel business Use of Hard-coded Credentials

Hard-coded credentials are used by the 
CyberPower PowerPanel 

 platform to authenticate to the 
database, other services, and the cloud. This could result in an 
attacker gaining access to services with the privileges of a Powerpanel 
business application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CyberpowerPowerpanel SwEditionbusiness SwPlatformwindows Version <= 4.9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.372
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ics-cert@hq.dhs.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads
Product
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01
Third Party Advisory
US Government Resource