CVE-2023-29412: OS Command Injection
A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
Other sources
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-29412?
CVE-2023-29412 is a CWE-78: Improper Handling of Case Sensitivity vulnerability.
What is the severity of CVE-2023-29412?
The severity of CVE-2023-29412 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2023-29412?
The software affected by CVE-2023-29412 is APC Easy UPS Online Monitoring Software version 2.5-ga-01-22320 and Easy UPS Online Monitoring Software version 2.5-gs-01-22320.
How can remote code execution occur in CVE-2023-29412?
Remote code execution can occur in CVE-2023-29412 when manipulating internal methods through Java RMI interface.
Is Microsoft Windows 10 affected by CVE-2023-29412?
No, Microsoft Windows 10 is not affected by CVE-2023-29412.