A specially crafted Zip file containing path traversal characters can be
imported to the
CyberPower PowerPanel
server, which allows file writing to the server outside
the intended scope, and could allow an attacker to achieve remote code
execution.
imported to the
CyberPower PowerPanel
server, which allows file writing to the server outside
the intended scope, and could allow an attacker to achieve remote code
execution.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-34477 | A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution. |
Fixes
Solution
CyberPower has released a new version (v4.10.1 or later version) of PowerPanel business that fixes these vulnerabilities. https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-02T02:36:04.306Z
Reserved: 2024-04-29T16:47:22.325Z
Link: CVE-2024-33615

Updated: 2024-05-16T15:13:19.064Z

Status : Awaiting Analysis
Published: 2024-05-15T20:15:12.687
Modified: 2024-11-21T09:17:15.217
Link: CVE-2024-33615

No data.

No data.