PT-2020-19613 · Apc · Apc Easy Ups On-Line

Published

2020-08-17

·

Updated

2020-09-04

·

CVE-2020-7521

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions APC Easy UPS On-Line Software versions V2.0 and earlier
Description The issue is related to a Path Traversal vulnerability when accessing a vulnerable method of FileUploadServlet. This may lead to uploading executable files to non-specified directories, potentially resulting in remote code execution.
Recommendations For APC Easy UPS On-Line Software versions V2.0 and earlier, consider disabling the FileUploadServlet until a patch is available to prevent potential exploitation. Restrict access to the FileUploadServlet method to minimize the risk of uploading executable files to unauthorized directories.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7521
ZDI-20-1006

Affected Products

Apc Easy Ups On-Line