PT-2023-2350 · Schneider Electric · Apc Easy Ups Online Monitoring+1

Publicado

2023-04-11

·

Atualizado

2024-06-12

·

CVE-2023-29412

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions APC Easy UPS Online Monitoring Software versions (affected versions not specified) Schneider Electric APC Easy UPS Online (affected versions not specified)
Description A vulnerability exists due to improper neutralization of special elements used in an OS command, which could cause remote code execution when manipulating internal methods through the Java RMI interface. This issue may allow a remote attacker to execute arbitrary code.
Recommendations For APC Easy UPS Online Monitoring Software, restrict access to the Java RMI interface until a patch is available. For Schneider Electric APC Easy UPS Online, avoid using the getMacAddressByIP function until the issue is resolved. As a temporary workaround, consider disabling the Java RMI interface to minimize the risk of exploitation.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02117
CVE-2023-29412
ZDI-23-445

Produtos afetados

Apc Easy Ups On-Line
Apc Easy Ups Online Monitoring