Local Privilege Escalation in Schneider Electric's Easy UPS Online Monitoring Software
CVE-2022-42973
7.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 1 February 2023
Summary
A vulnerability exists in Schneider Electric's Easy UPS Online Monitoring Software, which can allow a local attacker to escalate privileges by exploiting hard-coded credentials. This weakness arises when an attacker gains access to the database, risking unauthorized actions that could affect system integrity and reliability. Users are advised to update to the latest versions to mitigate this risk.
Affected Version(s)
APC Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022
Schneider Electric Easy UPS Online Monitoring Software Windows 7, 10, 11 Windows Server 2016, 2019, 2022
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved