Missing Authentication in APC Easy UPS Online Monitoring Software by Schneider Electric
CVE-2022-42970

9.8CRITICAL

Summary

The Easy UPS Online Monitoring Software by Schneider Electric exhibits a significant security vulnerability due to a lack of required authentication for critical functions. This flaw can potentially allow unauthorized users to access sensitive features or consume substantial system resources, posing a risk to system integrity and reliability. Users of affected versions are encouraged to update their software to mitigate potential security risks.

Affected Version(s)

APC Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022

APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022

Schneider Electric Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.