CVE-2022-0715
published 2022-03-09CVE-2022-0715: A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and…
PriorityP356critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
5.80%
92.3th percentile
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID=1020: UPS 10.4 and prior / SRT Series ID=1021: UPS 12.2 and prior / SRT Series ID=1001/1013: UPS 05.1 and prior / SRT Series ID=1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | scl_series_1029_ups_firmware | <= 02.5 | — |
| schneider-electric | scl_series_1030_ups_firmware | <= 02.5 | — |
| schneider-electric | scl_series_1036_ups_firmware | <= 02.5 | — |
| schneider-electric | scl_series_1037_ups_firmware | <= 03.1 | — |
| schneider-electric | smc_series_1005_ups_firmware | <= 14.1 | — |
| schneider-electric | smc_series_1007_ups_firmware | <= 11.0 | — |
| schneider-electric | smc_series_1018_ups_firmware | <= 04.2 | — |
| schneider-electric | smc_series_1041_ups_firmware | <= 01.1 | — |
| schneider-electric | smt_series_1015_ups_firmware | <= 04.5 | — |
| schneider-electric | smt_series_1031_ups_firmware | <= 03.1 | — |
| schneider-electric | smt_series_1040_ups_firmware | <= 01.2 | — |
| schneider-electric | smt_series_18_ups_firmware | <= 09.8 | — |
| schneider-electric | smtl_series_1026_ups_firmware | <= 02.9 | — |
| schneider-electric | smx_series_1031_ups_firmware | <= 03.1 | — |
| schneider-electric | smx_series_20_ups_firmware | <= 10.2 | — |
| schneider-electric | smx_series_23_ups_firmware | <= 07.0 | — |
| schneider-electric | srt_series_1001_ups_firmware | <= 05.1 | — |
| schneider-electric | srt_series_1002_ups_firmware | <= a05.2 | — |
| schneider-electric | srt_series_1010_ups_firmware | <= 08.3 | — |
| schneider-electric | srt_series_1013_ups_firmware | <= 05.1 | — |
| schneider-electric | srt_series_1014_ups_firmware | <= a05.2 | — |
| schneider-electric | srt_series_1019_ups_firmware | <= 08.3 | — |
| schneider-electric | srt_series_1020_ups_firmware | <= 10.4 | — |
| schneider-electric | srt_series_1021_ups_firmware | <= 12.2 | — |
| schneider-electric | srt_series_1025_ups_firmware | <= 08.3 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Schneider Electric SMT/SMC/SCL/SMX/SRT UPS improper authentication (SEVD-2022-067-02)
vuldb·2026-06-01·CVSS 9.1
CVE-2022-0715 [CRITICAL] Schneider Electric SMT/SMC/SCL/SMX/SRT UPS improper authentication (SEVD-2022-067-02)
A vulnerability was found in Schneider Electric SMT, SMC, SCL, SMX and SRT. It has been classified as critical. Affected is an unknown function of the component UPS Handler. This manipulation causes improper authentication.
The identification of this vulnerability is CVE-2022-0715. The attack needs to be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-fxwp-hqgp-45qg: A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leake
ghsa_unreviewed·2022-03-10
CVE-2022-0715 [CRITICAL] CWE-287 GHSA-fxwp-hqgp-45qg: A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leake
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID
No detection rules found.
No public exploits indexed.
2022-03-09
Published