Vulnerability Details CVE-2024-31856
An attacker with certain MQTT permissions can create malicious messages
to all CyberPower PowerPanel devices. This could result in an attacker injecting
SQL syntax, writing arbitrary files to the system, and executing remote
code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2024-31856
-
cpe:2.3:a:cyberpower:powerpanel:-
-
cpe:2.3:a:cyberpower:powerpanel:4.8.6
-
cpe:2.3:a:cyberpower:powerpanel:4.9.0