CVE-2023-29411
18.04.2023, 21:15
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | apc_easy_ups_online_monitoring_software | 𝑥 ≤ 2.5-ga-01-22320 |
schneider-electric | easy_ups_online_monitoring_software | 𝑥 ≤ 2.5-gs-01-22320 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration