Improper Authentication Vulnerability in APC Smart-UPS and SmartConnect Products
CVE-2022-0715
9.1CRITICAL
What is CVE-2022-0715?
An improper authentication vulnerability exists within specific APC Smart-UPS and SmartConnect models, allowing unauthorized access that may enable attackers to upload malicious firmware. This occurs if sensitive keys are compromised, leading to potentially undesired changes in UPS behavior. Ensuring proper authentication mechanisms are in place is critical, especially for devices managing power supply.
Affected Version(s)
APC Smart-UPS SMT Series
APC Smart-UPS SMC Series
APC Smart-UPS SCL Series