CVE-2024-32735
Homebrew vulnerability analysis and mitigation

Overview

A critical authentication bypass vulnerability exists in CyberPower PowerPanel Enterprise versions prior to v2.8.3. The vulnerability (CVE-2024-32735) allows an unauthenticated remote attacker to access the PDNU REST APIs without proper authentication, which could lead to a complete compromise of the application (NVD, Tenable Research).

Technical details

The vulnerability stems from missing authentication controls for certain utilities in the application. Specifically, unauthenticated attackers can access the PDNU REST APIs, which expose sensitive functionality. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating remote exploitation with no privileges or user interaction required (Tenable Research).

Impact

If exploited, this vulnerability allows attackers to access sensitive information including login credentials for devices managed by PDNU. Attackers can retrieve encrypted passwords which can be decrypted using a static key, potentially leading to full system compromise (Tenable Research).

Exploitability

The vulnerability is highly exploitable as it requires no authentication, privileges, or user interaction. Proof-of-concept code demonstrates the ability to fetch sensitive information including device credentials through unauthenticated API access (Tenable Research).

Mitigation and workarounds

Users should upgrade to CyberPower PowerPanel Enterprise version 2.8.3 or later to address this vulnerability. The fix has been released by the vendor and is available for download (CyberPower Release).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73939HIGH8.6
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73937HIGH8.2
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73938HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73936HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73935HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management