CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated...Show more |
A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage th...Show more |
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appen...Show more |
2Cyberpower Dataprobe23Iboot Pdu4 C20 Firmware Iboot Pdu4 N20 FirmwareIboot Pdu4a C10 Firmware+20 moreJun 17, 2026 Aug 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating syst...Show more |
2Cyberpower Dataprobe23Iboot Pdu4 C20 Firmware Iboot Pdu4 N20 FirmwareIboot Pdu4a C10 Firmware+20 moreJun 17, 2026 Aug 14, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavi...Show more |
2Cyberpower Dataprobe23Iboot Pdu4 C20 Firmware Iboot Pdu4 N20 FirmwareIboot Pdu4a C10 Firmware+20 moreJun 17, 2026 Aug 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute a...Show more |