GPU VulnDB

Database/Control plane, storage & DevOps

CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIs: Certain utility REST APIs have no authentication

CVE-2024-32735Control plane, storage & DevOpscurated

Impact

Certain utility REST APIs have no authentication at all, giving an unauthenticated remote attacker a direct route into the application. Yet another unauthenticated path into a system that controls power distribution - the pattern across this product line is that authentication is applied per-endpoint and repeatedly missed.

Who can reach it

Unauthenticated, remote, to the PowerPanel Enterprise API surface.

What to do

Upgrade to v2.8.3 or later. Given the density of unauthenticated findings in this product across 2023 and 2024, an operator should also decide whether it belongs in the design at all, or whether the power estate should be monitored through something with a better track record.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.