Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Powerpanel CRITICAL 9.8
CVE-2024-34025

CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing …

Fix: after 4.9.0
Fix from $2,300 2024-05-15
Powerpanel CRITICAL 9.8
CVE-2024-32047

Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining acce…

Fix: after 4.9.0
Fix from $2,300 2024-05-15
Powerpanel CRITICAL 9.8
CVE-2024-32053

Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could…

Fix: after 4.9.0
Fix from $2,300 2024-05-15
Powerpanel CRITICAL 9.8
CVE-2024-33625

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypas…

Fix: after 4.9.0
Fix from $2,300 2024-05-15
Powerpanel HIGH 8.8
CVE-2024-31856

An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injec…

Fix: after 4.9.0
Fix from $1,950 2024-05-15
Powerpanel HIGH 7.5
CVE-2024-31409

Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the sy…

Fix: after 4.9.0
Fix from $1,950 2024-05-15
Powerpanel HIGH 7.5
CVE-2024-32042

The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be …

Fix: after 4.9.0
Fix from $1,950 2024-05-15
Powerpanel MEDIUM 6.5
CVE-2024-31410

The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to im…

Fix: after 4.9.0
Fix from $1,600 2024-05-15
Powerpanel HIGH 7.5
CVE-2024-32737EPSS 5%

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor…

Fix: 2.8.3+
Fix from $1,950 2024-05-14
Powerpanel HIGH 7.5
CVE-2024-32738

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor…

Fix: 2.8.3+
Fix from $1,950 2024-05-14
Powerpanel HIGH 7.5
CVE-2024-32739EPSS 5%

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor…

Fix: 2.8.3+
Fix from $1,950 2024-05-14
Powerpanel CRITICAL 9.8
CVE-2024-32735EPSS 7%

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote…

Fix: 2.8.3+
Fix from $2,300 2024-05-14
Powerpanel HIGH 7.5
CVE-2024-32736EPSS 5%

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive infor…

Fix: 2.8.3+
Fix from $1,950 2024-05-14
Powerpanel Server CRITICAL 9.8
CVE-2023-3266

A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP…

Fix: 2.6.9+
Fix from $2,300 2023-08-14
Powerpanel Server HIGH 8.8
CVE-2023-3267

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without…

Fix: 2.6.9+
Fix from $1,950 2023-08-14
Powerpanel Server CRITICAL 9.8
CVE-2023-3264

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres…

Fix: 1.44.0804202 / 2.6.9+
Fix from $2,300 2023-08-14
Powerpanel Server CRITICAL 9.8
CVE-2023-3265

An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to…

Fix: 2.6.9+
Fix from $2,300 2023-08-14
Powerpanel Server HIGH 8.8
CVE-2023-3260

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An au…

Fix: 1.44.0804202 / 2.6.9+
Fix from $1,950 2023-08-14
Powerpanel Server HIGH 7.2
CVE-2023-3261

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Suc…

Fix: 1.44.0804202 / 2.6.9+
Fix from $1,950 2023-08-14
Powerpanel CRITICAL 9.8
CVE-2023-25133

Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Busine…

Fix: after 4.8.6
Fix from $2,300 2023-04-24
Powerpanel CRITICAL 9.8
CVE-2023-25131

Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows …

Fix: after 4.8.6
Fix from $2,300 2023-04-24
Powerpanel CRITICAL 9.8
CVE-2023-25132

Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier,…

Fix: after 4.8.6
Fix from $2,300 2023-04-24