CVE-2023-29413
published 2023-04-18CVE-2023-29413: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.71%
49.3th percentile
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause
Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor
service.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | apc_easy_ups_online_monitoring_software | <= 2.5-ga-01-22320 | — |
| schneider-electric | easy_ups_online_monitoring_software | <= 2.5-gs-01-22320 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vpvq-q686-fm5g: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause
Denial-of-Service when accessed by an unauthenticated us
ghsa_unreviewed·2023-04-18
CVE-2023-29413 [HIGH] CWE-306 GHSA-vpvq-q686-fm5g: A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause
Denial-of-Service when accessed by an unauthenticated us
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause
Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor
service.
CISA ICS
Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
cisa_ics·2024-06-11·CVSS 9.8
[CRITICAL] Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
ICS Advisory
##
Schneider Electric APC Easy UPS Online Monitoring Software (Update A)
Last RevisedJune 11, 2024
Alert CodeICSA-23-108-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity/Public exploits available
- Vendor: Schneider Electric
- Equipment: APC Easy UPS Online Monitoring Software
- Vulnerability: OS Command Injection, Missing Authentication for Critical Function
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could result in an attacker achieving remote code execution on the underlying operating system when manipulating internal methods through the Java RMI interface. It could also
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-18
Published