cbcvebase.
CVE-2023-29412
published 2023-04-18

CVE-2023-29412: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.22%
65.2th percentile
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.

Affected

2 ranges
VendorProductVersion rangeFixed in
schneider-electricapc_easy_ups_online_monitoring_software<= 2.5-ga-01-22320
schneider-electriceasy_ups_online_monitoring_software<= 2.5-gs-01-22320

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-29412 is exploitable via Java RMI interface — monitor for unexpected Java RMI connections (default port 1099) to APC Easy UPS Online Monitoring Software hosts
  • A public PoC exploit is available for this vulnerability; prioritize detection and patching of APC Easy UPS Online Monitoring Software v2.5-GA-01-22261 and prior (APC) and V2.5-GA-01-22320 and prior (Schneider Electric)
  • OS Command Injection via Java RMI interface manipulation — alert on OS command execution spawned from Java RMI service processes on Windows hosts running APC Easy UPS Online Monitoring Software
  • Affected platforms are Windows 10, 11, Windows Server 2016, 2019, 2022 — scope detection to these OS versions running the affected software
  • ·CVSS v3 base score is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) — network-exploitable with no authentication or user interaction required, making this critical for internet-exposed or network-accessible deployments
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.