9.8
CVE-2023-29411
- EPSS 5.99%
- Published 18.04.2023 21:15:09
- Last modified 21.11.2024 07:57:00
- Source cybersecurity@se.com
- Teams watchlist Login
- Open Login
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
Data is provided by the National Vulnerability Database (NVD)
Schneider-electric ≫ Apc Easy Ups Online Monitoring Software Version <= 2.5-ga-01-22320
Microsoft ≫ Windows 10 Version-
Microsoft ≫ Windows 11 Version- HwPlatform-
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2019 Version-
Microsoft ≫ Windows Server 2022 Version-
Microsoft ≫ Windows 11 Version- HwPlatform-
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2019 Version-
Microsoft ≫ Windows Server 2022 Version-
Schneider-electric ≫ Easy Ups Online Monitoring Software Version <= 2.5-gs-01-22320
Microsoft ≫ Windows 10 Version-
Microsoft ≫ Windows 11 Version- HwPlatform-
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2019 Version-
Microsoft ≫ Windows Server 2022 Version-
Microsoft ≫ Windows 11 Version- HwPlatform-
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2019 Version-
Microsoft ≫ Windows Server 2022 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 5.99% | 0.903 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
cybersecurity@se.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.