peter bassill · operator
$ cve CVE-2024-32735 JSON

CVE-2024-32735

9.8
CRITICAL · CVSS 3.1 · EPSS 6.8% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.77% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2024-05-14
Last modified2026-06-17

Affected (1)

VendorProduct
cyberpowerpowerpanel

References

→ the Explorer  ·  watch your stack  ·  NVD