CVE-2023-29413: High severity apc easy ups online monitoring software vulnerability
Published Apr 18, 2023
·Updated
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
Affected Software
7 affected components
Schneider-electric Apc Easy Ups Online Monitoring Software<=2.5-ga-01-22320
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Schneider-electric Easy Ups Online Monitoring Software<=2.5-gs-01-22320
Remediation
Event History
Apr 18, 2023
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-29413.
2
What is the severity of CVE-2023-29413?
The severity of CVE-2023-29413 is high with a score of 7.5.
3
How does CVE-2023-29413 impact the Schneider UPS Monitor service?
CVE-2023-29413 could cause a Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
4
Which software versions are affected by CVE-2023-29413?
The Schneider Electric APC Easy UPS Online Monitoring Software versions up to and including 2.5-ga-01-22320 and Easy UPS Online Monitoring Software versions up to and including 2.5-gs-01-22320 are affected by CVE-2023-29413.
5
How can I fix CVE-2023-29413?
To fix CVE-2023-29413, it is recommended to apply the necessary security patches provided by Schneider Electric.