CVE-2023-29411: Critical severity apc easy ups online monitoring software vulnerability
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-29411.
What is the severity of CVE-2023-29411?
The severity of CVE-2023-29411 is critical with a severity value of 9.8.
How does CVE-2023-29411 impact Schneider Electric APC Easy UPS Online Monitoring Software?
CVE-2023-29411 impacts Schneider Electric APC Easy UPS Online Monitoring Software versions up to 2.5-ga-01-22320 by allowing changes to administrative credentials without requiring prior authentication on the Java RMI interface, potentially leading to remote code execution.
Is Microsoft Windows 10 affected by CVE-2023-29411?
No, Microsoft Windows 10 is not vulnerable to CVE-2023-29411.
Is there a fix available for CVE-2023-29411?
Yes, a fix is available. Refer to the security and safety notice linked in the references for more information.