QID 378448

Date Published: 2023-05-24

QID 378448: Schneider Electric Easy UPS Online Monitoring Software Critical Vulnerabilities (SEVD-2023-101-04)

CVE-2023-29411:Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.

CVE-2023-29412:Improper Handling of Case Sensitivity vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.

CVE-2023-29413: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service

AFFECTED PRODUCTS
The following versions of APC Easy UPS Online Monitoring Software are affected:
Version prior to V2.5-GA-01-23036

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys uninstall string.

Successful exploitation of this vulnerability could lead to remote code execution,Denial-of-Service.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2023-101-04 for affected packages and patching details.

    Vendor References

    CVEs related to QID 378448

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2023-101-04 URL Logo download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-04.pdf