Missing Authentication in APC Easy UPS Online Monitoring Software by Schneider Electric
CVE-2022-42970
9.8CRITICAL
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 1 February 2023
What is CVE-2022-42970?
The Easy UPS Online Monitoring Software by Schneider Electric exhibits a significant security vulnerability due to a lack of required authentication for critical functions. This flaw can potentially allow unauthorized users to access sensitive features or consume substantial system resources, posing a risk to system integrity and reliability. Users of affected versions are encouraged to update their software to mitigate potential security risks.
Affected Version(s)
APC Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022
Schneider Electric Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022