Lucene search

K

SmartConnect Security Vulnerabilities

cve
cve

CVE-2022-22806

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS...

9.8CVSS

9.4AI Score

0.002EPSS

2022-03-09 08:15 PM
93
cve
cve

CVE-2022-22805

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series....

9.8CVSS

9.7AI Score

0.006EPSS

2022-03-09 08:15 PM
90
cve
cve

CVE-2022-0715

A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series...

9.1CVSS

9.2AI Score

0.001EPSS

2022-03-09 08:15 PM
53