A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface.
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-04.pdf | Mitigation Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
28 Apr 2023, 13:31
Type | Values Removed | Values Added |
---|---|---|
First Time |
Schneider-electric apc Easy Ups Online Monitoring Software
Schneider-electric Microsoft Microsoft windows 11 Microsoft windows Server 2019 Microsoft windows Server 2016 Microsoft windows 10 Microsoft windows Server 2022 Schneider-electric easy Ups Online Monitoring Software |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-04.pdf - Mitigation, Patch, Vendor Advisory | |
CPE | cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:-:* cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* cpe:2.3:a:schneider-electric:apc_easy_ups_online_monitoring_software:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* cpe:2.3:a:schneider-electric:easy_ups_online_monitoring_software:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
18 Apr 2023, 21:25
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-18 21:15
Updated : 2023-04-28 13:31
NVD link : CVE-2023-29411
Mitre link : CVE-2023-29411
JSON object : View
Products Affected
schneider-electric
- easy_ups_online_monitoring_software
- apc_easy_ups_online_monitoring_software
microsoft
- windows_10
- windows_11
- windows_server_2022
- windows_server_2016
- windows_server_2019
CWE
CWE-306
Missing Authentication for Critical Function