An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2024-05-15T19:52:37.407Z

Updated: 2024-06-04T17:36:10.715Z

Reserved: 2024-04-29T16:47:22.333Z


Link: CVE-2024-31856

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-05-15T20:15:11.710

Modified: 2024-05-16T13:03:05.353


Link: CVE-2024-31856

JSON object: View

cve-icon Redhat Information

No data.

CWE