CVE-2023-29411Missing Authentication for Critical Function in APC Easy UPS Online Monitoring Software

Severity
9.8CRITICALNVD
EPSS
8.3%
top 7.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18

Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qq2v-qm3v-4375: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potent2023-04-18
CVEList
CVE-2023-29411: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potent2023-04-18
CVE-2023-29411 — CRITICAL severity | cvebase