9.8

CVE-2023-29411

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface. 



Data is provided by the National Vulnerability Database (NVD)
Schneider-electricApc Easy Ups Online Monitoring Software Version <= 2.5-ga-01-22320
   MicrosoftWindows 10 Version-
   MicrosoftWindows 11 Version- HwPlatform-
   MicrosoftWindows Server 2016 Version-
   MicrosoftWindows Server 2019 Version-
   MicrosoftWindows Server 2022 Version-
Schneider-electricEasy Ups Online Monitoring Software Version <= 2.5-gs-01-22320
   MicrosoftWindows 10 Version-
   MicrosoftWindows 11 Version- HwPlatform-
   MicrosoftWindows Server 2016 Version-
   MicrosoftWindows Server 2019 Version-
   MicrosoftWindows Server 2022 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.99% 0.903
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cybersecurity@se.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.