GPU VulnDB

Database/Control plane, storage & DevOps

CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003: An unauthenticated attacker can repeatedly

CVE-2024-11322Control plane, storage & DevOpscurated

Impact

An unauthenticated attacker can repeatedly restart the ppbd.exe process via the watchdog service, keeping the power-management daemon permanently down. The consequence is not a crash you notice - it is that the software which would have gracefully shut down your fleet during a utility event is not running when the event happens. This is a denial of the safety mechanism, and its cost only materialises during the incident it was supposed to soften.

Who can reach it

Unauthenticated, to TCP/2003 on the host running PowerPanel Business.

What to do

Upgrade PowerPanel Business, and firewall TCP/2003 to only the hosts that legitimately need it. Also worth building: an alert on the power-management daemon being down, since the failure mode here is silence.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.