Path Traversal Vulnerability in APC Easy UPS On-Line Software by Schneider Electric
CVE-2020-7521

9.8CRITICAL

Key Information:

Summary

A path traversal vulnerability exists in Schneider Electric's APC Easy UPS On-Line Software (V2.0 and earlier), specifically within the FileUploadServlet method. This issue allows attackers to exploit improper limitations on file path access, potentially enabling unauthorized file uploads to non-restricted directories. Successful exploitation could compromise the system by allowing the upload of executable files, leading to further malicious actions.

Affected Version(s)

SFAPV9601 - APC Easy UPS On-Line Software V2.0 and earlier SFAPV9601 - APC Easy UPS On-Line Software V2.0 and earlier

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.