HTTP: CyberPower PowerPanel Business Import Profile Directory Traversal

This signature detects attempts to exploit a known vulnerability against CyberPower PowerPanel Business Import Profile. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution.

References

CVE: CVE-2024-33615

Short Name
HTTP:DIR:CYBERPOWER-IMP-PROFILE
Severity
Major
Recommended
True
Recommended Action
None
Category
HTTP
Keywords
Business CVE-2024-33615 CyberPower Directory Import PowerPanel Profile Traversal
Release Date
06/12/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3713
False Positive
Unknown

Found a potential security threat?