CVE-2023-29411
published 2023-04-18CVE-2023-29411: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.31%
67.4th percentile
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | apc_easy_ups_online_monitoring_software | <= 2.5-ga-01-22320 | — |
| schneider-electric | easy_ups_online_monitoring_software | <= 2.5-gs-01-22320 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the Java RMI interface for unauthenticated access attempts — CVE-2023-29411 allows changes to administrative credentials without prior authentication via this interface ↗
- →Monitor for unauthenticated manipulation of internal methods through the Java RMI interface on APC Easy UPS Online Monitoring Software hosts ↗
- →A public PoC exploit is available for this vulnerability; prioritize detection on hosts running APC Easy UPS Online Monitoring Software v2.5-GA-01-22261 and prior or Schneider Electric Easy UPS Online Monitoring Software V2.5-GA-01-22320 and prior ↗
- →Alert on unauthenticated access to the Schneider UPS Monitor service, which is exposed to denial-of-service via CVE-2023-29413 on the same attack surface ↗
- ·CVSS v3 base score is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) — network-exploitable with no privileges or user interaction required ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qq2v-qm3v-4375: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potent
ghsa_unreviewed·2023-04-18
CVE-2023-29411 [CRITICAL] CWE-306 GHSA-qq2v-qm3v-4375: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potent
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface.
CISA ICS
Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
cisa_ics·2024-06-11·CVSS 9.8
[CRITICAL] Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
ICS Advisory
##
Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
Last RevisedJune 11, 2024
Alert CodeICSA-23-108-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity/Public exploits available
- Vendor: Schneider Electric
- Equipment: APC Easy UPS Online Monitoring Software
- Vulnerability: OS Command Injection, Missing Authentication for Critical Function
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could result in an attacker achieving remote code execution on the underlying operating system when manipulating internal methods through the Java RMI interface. It could also
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-18
Published