9.8

CVE-2023-29411

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface. 



Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Apc Easy Ups Online Monitoring Software Version <= 2.5-ga-01-22320
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 11 Version - HwPlatform -
   Microsoft ≫ Windows Server 2016 Version -
   Microsoft ≫ Windows Server 2019 Version -
   Microsoft ≫ Windows Server 2022 Version -
Schneider-electric ≫ Easy Ups Online Monitoring Software Version <= 2.5-gs-01-22320
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 11 Version - HwPlatform -
   Microsoft ≫ Windows Server 2016 Version -
   Microsoft ≫ Windows Server 2019 Version -
   Microsoft ≫ Windows Server 2022 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.32% 0.67
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SE.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-04.pdf
Patch
Vendor Advisory
Mitigation