« Volver al listado

Schneider-electric

Schneider-electric Easy UPS Online Monitoring Software: vulnerabilidades y CVE

Schneider-electric Easy UPS Online Monitoring Software tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses0
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-6407Alta (7.1)0.24%—14 dic 2023
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged…
CVE-2023-29413Alta (7.5)0.71%—18 abr 2023
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
CVE-2023-29412Crítica (9.8)1.2%—18 abr 2023
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI…
CVE-2023-29411Crítica (9.8)1.3%—18 abr 2023
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on…
CVE-2022-42973Alta (7.8)0.16%—1 feb 2023
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows…
CVE-2022-42972Alta (7.8)0.18%—1 feb 2023
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS…
CVE-2022-42971Crítica (9.8)1.1%—1 feb 2023
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring…
CVE-2022-42970Crítica (9.8)0.71%—1 feb 2023
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected…

Otros productos de Schneider-electric