PT-2020-19614 · Apc · Apc Easy Ups On-Line

Published

2020-08-17

·

Updated

2020-09-04

·

CVE-2020-7522

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions APC Easy UPS On-Line Software versions V2.0 and earlier
Description The issue is related to a Path Traversal vulnerability when accessing a vulnerable method of SoundUploadServlet. This may lead to uploading executable files to non-specified directories, potentially resulting in remote code execution.
Recommendations For APC Easy UPS On-Line Software versions V2.0 and earlier, consider disabling the SoundUploadServlet until a patch is available to prevent potential exploitation. Restrict access to the processRequest method of SoundUploadServlet to minimize the risk of remote code execution.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7522
ZDI-20-1007

Affected Products

Apc Easy Ups On-Line