Database/Control plane, storage & DevOps

CyberPower PowerPanel business application - hardcoded authentication credentials: A hardcoded credential set compiled
Impact
A hardcoded credential set compiled into the application gives administrator access to anyone who reads the binary. There is no configuration that removes it and no password rotation that helps. On a platform that controls power distribution, this is a permanent unauthenticated back door until the vendor ships a build without it.
Who can reach it
Unauthenticated, remote, using credentials extractable from the shipped software by anyone.
What to do
Upgrade to a build that removes the credentials - configuration changes cannot help. Until upgraded, the only real control is network isolation: the PowerPanel host must be unreachable from anything but a management jump box.
References
Related entries
- Volcano (v1.8.2 and earlier, service account token permissions): Volcano 1.8.2 ships over-permissive settings that letCVE-2024-36533 · Volcano (v1.8.2 and earlier, service account token permissions)Critical
- VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticatedCVE-2024-37080 · VMware vCenter Server (DCERPC heap overflow)Critical
- Terraform (go-getter): Argument injection when go-getter shells out to Git for remote branch discoveryCVE-2024-3817 · Terraform (go-getter)Critical
- Veeam Backup & Replication: Deserialization of untrusted dataCVE-2024-40711 · Veeam Backup & ReplicationCritical
- Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP serverCVE-2024-4323 · Fluent BitCritical
- Fortinet FortiManager: "FortiJump" - missing authentication in fgfmdCVE-2024-47575 · Fortinet FortiManagerCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.