Database/Control plane, storage & DevOps

CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003: An unauthenticated attacker can repeatedly
Impact
An unauthenticated attacker can repeatedly restart the ppbd.exe process via the watchdog service, keeping the power-management daemon permanently down. The consequence is not a crash you notice - it is that the software which would have gracefully shut down your fleet during a utility event is not running when the event happens. This is a denial of the safety mechanism, and its cost only materialises during the incident it was supposed to soften.
Who can reach it
Unauthenticated, to TCP/2003 on the host running PowerPanel Business.
What to do
Upgrade PowerPanel Business, and firewall TCP/2003 to only the hosts that legitimately need it. Also worth building: an alert on the power-management daemon being down, since the failure mode here is silence.
References
Related entries
- OpenVPN: The interactive service pipe is reachable remotelyCVE-2024-24974 · OpenVPNHigh
- Intel Neural Compressor: Unauthenticated input-validation failure leading to escalation of privilege in NeuralCVE-2024-28028 · Intel Neural CompressorHigh
- Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0a: Three defects that together mean every SANnav OVACVE-2024-29966 · Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0aHigh
- AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014): The BadRAM SPD-aliasing technique aimed atCVE-2024-36354 · AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014)High
- Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an emptyCVE-2024-47866 · Ceph RADOS Gateway (RGW)High
- Sonatype Nexus Repository 3: Unauthenticated path traversalCVE-2024-4956 · Sonatype Nexus Repository 3High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.