Database/Control plane, storage & DevOps

CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default password
Impact
A default password that ships enabled. This is the most boring vulnerability in the facility layer and probably the most exploited class of them in practice - power management software gets installed once by whoever racked the gear and never revisited.
Who can reach it
Unauthenticated remote access to the PowerPanel Business interface using published default credentials.
What to do
Upgrade past v4.8.6 and change the credential. Then go and check every other piece of power-management software you inherited with a build: default credentials on facility gear are the single highest-yield internal audit an operator can run, and it costs a day.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.