PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-34025 CyberPower CVE debrief

CyberPower PowerPanel Business versions 4.9.0 and earlier contain hard-coded authentication credentials in the application code. This vulnerability allows an unauthenticated attacker to bypass authentication and gain administrator privileges on affected systems. The issue was disclosed by CISA on May 2, 2024, with a CVSS 3.0 score of 9.8 (Critical). CyberPower has released version 4.10.1 to address this vulnerability. Organizations using affected versions should prioritize patching, as this vulnerability requires no user interaction and can be exploited remotely over the network.

Vendor
CyberPower
Product
PowerPanel Business
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-05-02
Original CVE updated
2025-08-07
Advisory published
2024-05-02
Advisory updated
2025-08-07

Who should care

Organizations using CyberPower PowerPanel Business for UPS management in data centers, industrial facilities, or critical infrastructure environments. Security teams responsible for industrial control systems and operational technology infrastructure. System administrators managing power infrastructure with remote management capabilities.

Technical summary

CVE-2024-34025 is a critical vulnerability in CyberPower PowerPanel Business ≤4.9.0 caused by hard-coded authentication credentials embedded in the application code. The vulnerability has a CVSS 3.0 score of 9.8 (Critical) with attack vector Network, attack complexity Low, and no privileges or user interaction required. Successful exploitation allows complete compromise of confidentiality, integrity, and availability of the affected system. The vulnerability was disclosed on May 2, 2024, and remediated by CyberPower in version 4.10.1 released thereafter.

Defensive priority

critical

Recommended defensive actions

  • Upgrade CyberPower PowerPanel Business to version 4.10.1 or later immediately
  • If immediate patching is not possible, restrict network access to PowerPanel Business management interfaces to trusted administrative hosts only
  • Monitor for unauthorized administrative access attempts in PowerPanel Business audit logs
  • Review and rotate any credentials that may have been compromised prior to patching
  • Apply defense-in-depth controls per CISA ICS recommended practices for industrial control systems

Evidence notes

CISA ICS advisory ICSA-24-123-01 confirms hard-coded credentials in PowerPanel Business ≤4.9.0 enabling authentication bypass with administrator privilege escalation. CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Vendor fix released in v4.10.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-34025 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-34025

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-34025 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-34025

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-123-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.