CVE-2023-29412

CRITICAL

APC Easy UPS Online Monitoring Software < 2.5 Remote Code Execution via Java RMI

Title source: llm
STIX 2.1

Description

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.

Scores

CVSS v3 9.8
EPSS 0.0254
EPSS Percentile 85.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
schneider-electric/apc_easy_ups_online_monitoring_software < 2.5-ga-01-22320
schneider-electric/easy_ups_online_monitoring_software < 2.5-gs-01-22320
Published Apr 18, 2023
Tracked Since Feb 18, 2026