Database/Control plane, storage & DevOps

CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIs: Certain utility REST APIs have no authentication
Impact
Certain utility REST APIs have no authentication at all, giving an unauthenticated remote attacker a direct route into the application. Yet another unauthenticated path into a system that controls power distribution - the pattern across this product line is that authentication is applied per-endpoint and repeatedly missed.
Who can reach it
Unauthenticated, remote, to the PowerPanel Enterprise API surface.
What to do
Upgrade to v2.8.3 or later. Given the density of unauthenticated findings in this product across 2023 and 2024, an operator should also decide whether it belongs in the design at all, or whether the power estate should be monitored through something with a better track record.
References
Related entries
- CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, soCVE-2024-33625 · CyberPower PowerPanel business application - JWT signing keyCritical
- CyberPower PowerPanel business application - hardcoded authentication credentials: A hardcoded credential set compiledCVE-2024-34025 · CyberPower PowerPanel business application - hardcoded authentication credentialsCritical
- Volcano (v1.8.2 and earlier, service account token permissions): Volcano 1.8.2 ships over-permissive settings that letCVE-2024-36533 · Volcano (v1.8.2 and earlier, service account token permissions)Critical
- VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticatedCVE-2024-37080 · VMware vCenter Server (DCERPC heap overflow)Critical
- Terraform (go-getter): Argument injection when go-getter shells out to Git for remote branch discoveryCVE-2024-3817 · Terraform (go-getter)Critical
- Veeam Backup & Replication: Deserialization of untrusted dataCVE-2024-40711 · Veeam Backup & ReplicationCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.