← back
CVE-2024-32735criticalobserved exploitationCWE-306

CyberPower PowerPanel Enterprise Missing Authentication

65Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 6.8%
from disclosure to weapon
Published on NVDMay 9
VulnCheck+258d
exploitation probability
6.8%top 6% of all CVEs
observed exploitation
yesVulnCheck
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H