Lucene search

K
cve[email protected]CVE-2023-29412
HistoryApr 18, 2023 - 9:15 p.m.

CVE-2023-29412

2023-04-1821:15:09
CWE-78
web.nvd.nist.gov
60
2
cve-2023-29412
cwe-78
improper handling
case sensitivity
java rmi
remote code execution

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.5%

CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command
Injection’) vulnerability exists that could cause remote code execution when manipulating
internal methods through Java RMI interface.

Affected configurations

NVD
Node
schneider-electricapc_easy_ups_online_monitoring_softwareRange2.5-ga-01-22320
AND
microsoftwindows_10Match-
OR
microsoftwindows_11Match--
OR
microsoftwindows_server_2016Match-
OR
microsoftwindows_server_2019Match-
OR
microsoftwindows_server_2022Match-
Node
schneider-electriceasy_ups_online_monitoring_softwareRange2.5-gs-01-22320
AND
microsoftwindows_10Match-
OR
microsoftwindows_11Match--
OR
microsoftwindows_server_2016Match-
OR
microsoftwindows_server_2019Match-
OR
microsoftwindows_server_2022Match-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "APC Easy UPS Online Monitoring Software (Windows 10, 11 Windows Server 2016, 2019, 2022)",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "lessThanOrEqual": "prior",
        "status": "affected",
        "version": "V2.5-GA-01-22320",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Schneider Electric Easy UPS Online Monitoring Software (Windows 10, 11 Windows Server 2016, 2019, 2022)",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "lessThanOrEqual": "prior",
        "status": "affected",
        "version": "V2.5-GS-01-22320",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.5%

Related for CVE-2023-29412