A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory
Published Feb 1, 2023
7.8
HIGHCVSS 3.1
EPSS 0.18%
Description
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Affected products
-
Affected
- ≥ (Windows 11, Windows Server 2019, 2022, < V2.5-GA-01-22261
- ≥ Windows 7, 10, 11 Windows Server 2016, 2019, 2022, < V2.5-GA
- Vendor Schneider Electric Product Schneider Electric Easy UPS Online Monitoring Software Defaultunknown
Affected
- ≥ Windows 11, Windows Server 2019, 2022, < V2.5-GS-01-22261
- ≥ Windows 7, 10, 11 Windows Server 2016, 2019, 2022, < V2.5-GS
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Schneider Electric | APC Easy UPS Online Monitoring Software | unknown | Affected
|
| Schneider Electric | Schneider Electric Easy UPS Online Monitoring Software | unknown | Affected
|
Configuration 1
- < 2.5-ga-01-22320
Running on/with
- n/a
- n/a
- n/a
Configuration 2
- < 2.5-gs-01-22320
Running on/with
- n/a
- n/a
- n/a
Configuration 3
- < 2.5-ga
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 4
- < 2.5-gs
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://download.schneider-electric.com/files?p_Doc_SEVD-2022-347-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-347-01_Easy_UPS_Online_Monitoring_Software_Security_Notification.pdf PatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-46022 Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data