Unrestricted File Upload Vulnerability in APC Easy UPS Online Monitoring Software by Schneider Electric
CVE-2022-42971
9.8CRITICAL
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 1 February 2023
Summary
The APC Easy UPS Online Monitoring Software is susceptible to an Unrestricted Upload of File with Dangerous Type vulnerability. This weakness allows an attacker to upload a malicious JSP file, which could potentially lead to remote code execution. Users of affected versions should prioritize updating their software to mitigate risks associated with unauthorized file uploads.
Affected Version(s)
APC Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022
Schneider Electric Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved