CVE-2024-32042
CyberPower PowerPanel business Storing Passwords in a Recoverable Format
Severity Score
4.9
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
The key used to encrypt passwords stored in the database can be found in
the
CyberPower PowerPanel
application code, allowing the passwords to be recovered.
La clave utilizada para cifrar las contraseñas almacenadas en la base de datos se puede encontrar en el código de la aplicación CyberPower PowerPanel, lo que permite recuperar las contraseñas.
*Credits:
Amir Preminger and Noam Moshe of Claroty Team82 Research reported these vulnerabilities to CISA.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-04-29 CVE Reserved
- 2024-05-15 CVE Published
- 2024-05-16 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-257: Storing Passwords in a Recoverable Format
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01 | ||
https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
CyberPower Search vendor "CyberPower" | PowerPanel Business Search vendor "CyberPower" for product "PowerPanel Business" | < 4.9.0 Search vendor "CyberPower" for product "PowerPanel Business" and version " < 4.9.0" | en |
Affected
|