CVE-2023-29412
published 2023-04-18CVE-2023-29412: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.22%
65.2th percentile
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command
Injection') vulnerability exists that could cause remote code execution when manipulating
internal methods through Java RMI interface.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | apc_easy_ups_online_monitoring_software | <= 2.5-ga-01-22320 | — |
| schneider-electric | easy_ups_online_monitoring_software | <= 2.5-gs-01-22320 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-29412 is exploitable via Java RMI interface — monitor for unexpected Java RMI connections (default port 1099) to APC Easy UPS Online Monitoring Software hosts ↗
- →A public PoC exploit is available for this vulnerability; prioritize detection and patching of APC Easy UPS Online Monitoring Software v2.5-GA-01-22261 and prior (APC) and V2.5-GA-01-22320 and prior (Schneider Electric) ↗
- →OS Command Injection via Java RMI interface manipulation — alert on OS command execution spawned from Java RMI service processes on Windows hosts running APC Easy UPS Online Monitoring Software ↗
- →Affected platforms are Windows 10, 11, Windows Server 2016, 2019, 2022 — scope detection to these OS versions running the affected software ↗
- ·CVSS v3 base score is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) — network-exploitable with no authentication or user interaction required, making this critical for internet-exposed or network-accessible deployments ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7p8q-cvq9-54g6: A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote
code execution when manipulating internal methods through
ghsa_unreviewed·2023-04-18
CVE-2023-29412 [CRITICAL] CWE-78 GHSA-7p8q-cvq9-54g6: A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote
code execution when manipulating internal methods through
A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote
code execution when manipulating internal methods through Java RMI interface.
CISA ICS
Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
cisa_ics·2024-06-11·CVSS 9.8
[CRITICAL] Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
ICS Advisory
##
Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
Last RevisedJune 11, 2024
Alert CodeICSA-23-108-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity/Public exploits available
- Vendor: Schneider Electric
- Equipment: APC Easy UPS Online Monitoring Software
- Vulnerability: OS Command Injection, Missing Authentication for Critical Function
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could result in an attacker achieving remote code execution on the underlying operating system when manipulating internal methods through the Java RMI interface. It could also
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-18
Published