Unrestricted File Upload Vulnerability in APC Easy UPS Online Monitoring Software by Schneider Electric
CVE-2022-42971
9.8CRITICAL
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 1 February 2023
What is CVE-2022-42971?
The APC Easy UPS Online Monitoring Software is susceptible to an Unrestricted Upload of File with Dangerous Type vulnerability. This weakness allows an attacker to upload a malicious JSP file, which could potentially lead to remote code execution. Users of affected versions should prioritize updating their software to mitigate risks associated with unauthorized file uploads.
Affected Version(s)
APC Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022
Schneider Electric Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022