Certain MQTT wildcards are not blocked on the
CyberPower PowerPanel
system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01 | Third Party Advisory US Government Resource |
https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads | Product |
https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01 | Third Party Advisory US Government Resource |
https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads | Product |
Configurations
History
07 Aug 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 |
30 Jul 2025, 00:29
Type | Values Removed | Values Added |
---|---|---|
First Time |
Cyberpower
Cyberpower powerpanel |
|
CPE | cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:* | |
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01 - Third Party Advisory, US Government Resource | |
References | () https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads - Product |
21 Nov 2024, 09:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01 - | |
References | () https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads - |
16 May 2024, 13:03
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 May 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-15 20:15
Updated : 2025-08-07 19:15
NVD link : CVE-2024-31409
Mitre link : CVE-2024-31409
CVE.ORG link : CVE-2024-31409
JSON object : View
Products Affected
cyberpower
- powerpanel
CWE
CWE-863
Incorrect Authorization