The devices which CyberPower PowerPanel manages use identical certificates based on a
hard-coded cryptographic key. This can allow an attacker to impersonate
any client in the system and send malicious data.

Project Subscriptions

Vendors Products
Cyberpower Subscribe
Powerpanel Subscribe
Powerpanel Business Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-34451 The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data.
Fixes

Solution

CyberPower has released a new version (v4.10.1 or later version) of PowerPanel business that fixes these vulnerabilities. https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads


Workaround

No workaround given by the vendor.

History

Wed, 30 Jul 2025 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyberpower powerpanel
CPEs cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:business:windows:*:*
Vendors & Products Cyberpower powerpanel

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-02T01:52:56.912Z

Reserved: 2024-04-29T16:47:22.319Z

Link: CVE-2024-31410

cve-icon Vulnrichment

Updated: 2024-05-16T19:05:45.481Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-15T20:15:11.473

Modified: 2025-07-30T00:23:54.457

Link: CVE-2024-31410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses