PT-2022-5907 · Schneider Electric · Apc Easy Ups Online Monitoring+1
Published
2022-12-13
·
Updated
2023-05-17
·
CVE-2022-42971
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
APC Easy UPS Online Monitoring Software versions prior to V2.5-GA
APC Easy UPS Online Monitoring Software versions prior to V2.5-GA-01-22261
Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS
Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS-01-22261
Description
A vulnerability exists that could cause remote code execution when an attacker uploads a malicious JSP file. This issue is related to the unrestricted upload of files with dangerous types. The exploitation of this vulnerability may allow a remote attacker to execute arbitrary code by uploading an arbitrary JSP file.
Recommendations
For APC Easy UPS Online Monitoring Software versions prior to V2.5-GA, update to version V2.5-GA or later.
For APC Easy UPS Online Monitoring Software versions prior to V2.5-GA-01-22261, update to version V2.5-GA-01-22261 or later.
For Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS, update to version V2.5-GS or later.
For Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS-01-22261, update to version V2.5-GS-01-22261 or later.
As a temporary workaround, consider restricting the upload of JSP files to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apc Easy Ups Online Monitoring
Schneider Electric Easy Ups Online Monitoring