A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file
Published Feb 1, 2023
9.8
CRITICALCVSS 3.1
EPSS 1.07%
Description
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Affected products
-
- Version (Windows 11, Windows Server 2019, 2022StatusaffectedConstraints<V2.5-GA-01-22261
- Version Windows 7, 10, 11 Windows Server 2016, 2019, 2022StatusaffectedConstraints<V2.5-GA
- Version
- Vendor Schneider Electric Product Schneider Electric Easy UPS Online Monitoring Software Defaultn/a
- Version Windows 11, Windows Server 2019, 2022StatusaffectedConstraints<V2.5-GS-01-22261
- Version Windows 7, 10, 11 Windows Server 2016, 2019, 2022StatusaffectedConstraints<V2.5-GS
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Schneider Electric | APC Easy UPS Online Monitoring Software | n/a |
| |||||||||
| Schneider Electric | Schneider Electric Easy UPS Online Monitoring Software | n/a |
|
Configuration 1
- < 2.5-ga-01-22320
Running on/with
- n/a
- n/a
- n/a
Configuration 2
- < 2.5-gs-01-22320
Running on/with
- n/a
- n/a
- n/a
Configuration 3
- < 2.5-ga
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 4
- < 2.5-gs
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
Change history (0)
No recorded changes yet.