PT-2022-5907 · Schneider Electric · Apc Easy Ups Online Monitoring+1

CVE-2022-42971

·

Published

2022-12-13

·

Updated

2023-05-17

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions APC Easy UPS Online Monitoring Software versions prior to V2.5-GA APC Easy UPS Online Monitoring Software versions prior to V2.5-GA-01-22261 Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS-01-22261
Description A vulnerability exists that could cause remote code execution when an attacker uploads a malicious JSP file. This issue is related to the unrestricted upload of files with dangerous types. The exploitation of this vulnerability may allow a remote attacker to execute arbitrary code by uploading an arbitrary JSP file.
Recommendations For APC Easy UPS Online Monitoring Software versions prior to V2.5-GA, update to version V2.5-GA or later. For APC Easy UPS Online Monitoring Software versions prior to V2.5-GA-01-22261, update to version V2.5-GA-01-22261 or later. For Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS, update to version V2.5-GS or later. For Schneider Electric Easy UPS Online Monitoring Software versions prior to V2.5-GS-01-22261, update to version V2.5-GS-01-22261 or later. As a temporary workaround, consider restricting the upload of JSP files to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-07323
CVE-2022-42971
ZDI-23-637

Affected Products

Apc Easy Ups Online Monitoring
Schneider Electric Easy Ups Online Monitoring