PT-2022-9284 · Apc · Symmetra+19
Published
2022-01-28
·
Updated
2022-02-04
·
CVE-2021-22814
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
APC Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2) versions prior to NMC2 AOS V6.9.8
APC Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2) versions prior to NMC2 AOS V6.9.6
APC Symmetra PX 48/96/100/160 kW UPS (PX2), Symmetra PX 20/40 kW UPS (SY3P), Gutor (SXW, GVX), and Galaxy (GVMTS, GVMSA, GVXTS, GVXSA, G7K, GFC, G9KCHU) with Network Management Card 2 (NMC2) versions prior to NMC2 AOS V6.9.6
APC Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 3 (NMC3) versions prior to NMC3 AOS V1.4.2.1
APC Rack Power Distribution Units (PDU) using NMC2 2G Metered/Switched Rack PDUs with embedded NMC2 versions prior to NMC2 AOS V6.9.6
APC Rack Power Distribution Units (PDU) using NMC3 2G Metered/Switched Rack PDUs with embedded NMC3 versions prior to NMC3 AOS V1.4.0
APC 3-Phase Power Distribution Products using NMC2 Galaxy RPP versions prior to NMC2 AOS V6.9.6
Network Management Card 2 (NMC2) for InfraStruxure 150 kVA PDU with 84 Poles (X84P) versions prior to NMC2 AOS V6.9.6
Network Management Card 2 for InfraStruxure 40/60kVA PDU (XPDU) versions prior to NMC2 AOS V6.9.6
Network Management Card 2 for Modular 150/175kVA PDU (XRDP) versions prior to NMC2 AOS V6.9.6
Network Management Card 2 for 400 and 500 kVA (PMM) versions prior to NMC2 AOS V6.9.6
Network Management Card 2 for Modular PDU (XRDP2G) versions prior to NMC2 AOS V6.9.6
Rack Automatic Transfer Switches (ATS) Embedded NMC2 versions prior to NMC2 AOS V6.9.6
Network Management Card 2 (NMC2) Cooling Products versions prior to NMC2 AOS V6.9.6
Environmental Monitoring Unit with embedded NMC2 (NB250) versions prior to NMC2 AOS V6.9.6
Network Management Card 2 (NMC2): AP9922 Battery Management System (BM4) versions prior to NMC2 AOS V6.9.6
Description
A Cross-site Scripting vulnerability exists which could cause arbitrary script execution when a malicious file is read and displayed.
Recommendations
For APC Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2), update to NMC2 AOS V6.9.8 or later.
For APC Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2), update to NMC2 AOS V6.9.6 or later.
For APC Symmetra PX 48/96/100/160 kW UPS (PX2), Symmetra PX 20/40 kW UPS (SY3P), Gutor (SXW, GVX), and Galaxy (GVMTS, GVMSA, GVXTS, GVXSA, G7K, GFC, G9KCHU) with Network Management Card 2 (NMC2), update to NMC2 AOS V6.9.6 or later.
For APC Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 3 (NMC3), update to NMC3 AOS V1.4.2.1 or later.
For APC Rack Power Distribution Units (PDU) using NMC2 2G Metered/Switched Rack PDUs with embedded NMC2, update to NMC2 AOS V6.9.6 or later.
For APC Rack Power Distribution Units (PDU) using NMC3 2G Metered/Switched Rack PDUs with embedded NMC3, update to NMC3 AOS V1.4.0 or later.
For APC 3-Phase Power Distribution Products using NMC2 Galaxy RPP, update to NMC2 AOS V6.9.6 or later.
For Network Management Card 2 (NMC2) for InfraStruxure 150 kVA PDU with 84 Poles (X84P), update to NMC2 AOS V6.9.6 or later.
For Network Management Card 2 for InfraStruxure 40/60kVA PDU (XPDU), update to NMC2 AOS V6.9.6 or later.
For Network Management Card 2 for Modular 150/175kVA PDU (XRDP), update to NMC2 AOS V6.9.6 or later.
For Network Management Card 2 for 400 and 500 kVA (PMM), update to NMC2 AOS V6.9.6 or later.
For Network Management Card 2 for Modular PDU (XRDP2G), update to NMC2 AOS V6.9.6 or later.
For Rack Automatic Transfer Switches (ATS) Embedded NMC2, update to NMC2 AOS V6.9.6 or later.
For Network Management Card 2 (NMC2) Cooling Products, update to NMC2 AOS V6.9.6 or later.
For Environmental Monitoring Unit with embedded NMC2 (NB250), update to NMC2 AOS V6.9.6 or later.
For Network Management Card 2 (NMC2): AP9922 Battery Management System (BM4), update to NMC2 AOS V6.9.6 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
400/500 Kva
Ap9922 Battery Management System
Apc 3-Phase Power Distribution Products
Apc Rack Power Distribution Units
Apc Smart-Ups
Apc Symmetra Px 250/500
Apc Symmetra Px 48/96/100/160 Kw Ups
Environmental Monitoring Unit
Galaxy
Galaxy 3500
Gutor
Infrastruxure 150 Kva Pdu
Infrastruxure 40/60Kva Pdu
Modular 150/175Kva Pdu
Modular Pdu
Network Management Card 2
Network Management Card 3
Rack Automatic Transfer Switches
Symmetra
Symmetra Px 20/40 Kw Ups