GPU VulnDB

Database/Control plane, storage & DevOps

CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default password

CVE-2023-25131Control plane, storage & DevOpsJVN#95119483curated

Impact

A default password that ships enabled. This is the most boring vulnerability in the facility layer and probably the most exploited class of them in practice - power management software gets installed once by whoever racked the gear and never revisited.

Who can reach it

Unauthenticated remote access to the PowerPanel Business interface using published default credentials.

What to do

Upgrade past v4.8.6 and change the credential. Then go and check every other piece of power-management software you inherited with a build: default credentials on facility gear are the single highest-yield internal audit an operator can run, and it costs a day.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.