CVE-2020-7521: Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of FileUploadServlet which may lead to uploading executable files to non-specified directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7521?
The severity of CVE-2020-7521 is critical with a CVSS score of 9.8.
What is CVE-2020-7521?
CVE-2020-7521 is a vulnerability that allows for Path Traversal in Schneider Electric APC Easy UPS On-Line Software.
How does CVE-2020-7521 affect Schneider Electric APC Easy UPS On-Line Software?
CVE-2020-7521 allows attackers to upload executable files to non-specified directories in Schneider Electric APC Easy UPS On-Line Software.
How can I mitigate the CVE-2020-7521 vulnerability?
To mitigate the CVE-2020-7521 vulnerability, it is recommended to update SFAPV9601 - APC Easy UPS On-Line Software to version 2.1 or later.
Where can I find more information about CVE-2020-7521?
You can find more information about CVE-2020-7521 on the Schneider Electric website at https://www.se.com/ww/en/download/document/SEVD-2020-224-04/.