CyberPower PowerPanel
system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34450 | Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device. |
Solution
CyberPower has released a new version (v4.10.1 or later version) of PowerPanel business that fixes these vulnerabilities. https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads
Workaround
No workaround given by the vendor.
Thu, 07 Aug 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Thu, 07 Aug 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CyberPower PowerPanel business Improper Authorization | CyberPower PowerPanel business Incorrect Authorization |
| Weaknesses | CWE-863 |
Wed, 30 Jul 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cyberpower powerpanel
|
|
| CPEs | cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:* | |
| Vendors & Products |
Cyberpower powerpanel
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-08-07T18:26:54.578Z
Reserved: 2024-04-29T16:47:22.337Z
Link: CVE-2024-31409
Updated: 2024-08-02T01:52:56.873Z
Status : Modified
Published: 2024-05-15T20:15:11.203
Modified: 2025-08-07T19:15:28.180
Link: CVE-2024-31409
No data.
OpenCVE Enrichment
No data.
EUVD