CVE-2024-33615
Severity CVSS v4.0:
Pending analysis
Type:
CWE-23
Relative Path Traversal
Publication date:
15/05/2024
Last modified:
15/04/2026
Description
A specially crafted Zip file containing path traversal characters can be<br />
imported to the <br />
CyberPower PowerPanel <br />
<br />
server, which allows file writing to the server outside<br />
the intended scope, and could allow an attacker to achieve remote code <br />
execution.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01
- https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01
- https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads



