Description
A specially crafted Zip file containing path traversal characters can be
imported to the
CyberPower PowerPanel
server, which allows file writing to the server outside
the intended scope, and could allow an attacker to achieve remote code
execution.
imported to the
CyberPower PowerPanel
server, which allows file writing to the server outside
the intended scope, and could allow an attacker to achieve remote code
execution.
No analysis available yet.
Remediation
Vendor Solution
CyberPower has released a new version (v4.10.1 or later version) of PowerPanel business that fixes these vulnerabilities. https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34477 | A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution. |
References
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-02T02:36:04.306Z
Reserved: 2024-04-29T16:47:22.325Z
Link: CVE-2024-33615
Updated: 2024-05-16T15:13:19.064Z
Status : Awaiting Analysis
Published: 2024-05-15T20:15:12.687
Modified: 2024-11-21T09:17:15.217
Link: CVE-2024-33615
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD