First published: Tue Jun 11 2024(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric APC Easy UPS Online. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Apc Easy Ups Online Monitoring Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-24-600 is rated at 9.8 on the CVSS scale, indicating critical vulnerability.
To fix ZDI-24-600, update to the latest security release provided by Schneider Electric for the APC Easy UPS Online.
ZDI-24-600 allows remote attackers to execute arbitrary code on affected installations without authentication.
ZDI-24-600 affects the Schneider Electric APC Easy UPS Online monitoring software.
No, authentication is not required to exploit the vulnerability ZDI-24-600.