An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-05-15T19:52:37.407Z

Updated: 2024-08-02T01:59:49.843Z

Reserved: 2024-04-29T16:47:22.333Z

Link: CVE-2024-31856

cve-icon Vulnrichment

Updated: 2024-05-16T18:09:22.415Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T20:15:11.710

Modified: 2024-11-21T09:14:01.757

Link: CVE-2024-31856

cve-icon Redhat

No data.