CVE-2023-29412
CRITICALAPC Easy UPS Online Monitoring Software < 2.5 Remote Code Execution via Java RMI
Title source: llmDescription
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
References (1)
Core 1
Core References
Scores
CVSS v3
9.8
EPSS
0.0254
EPSS Percentile
85.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
schneider-electric/apc_easy_ups_online_monitoring_software
< 2.5-ga-01-22320
schneider-electric/easy_ups_online_monitoring_software
< 2.5-gs-01-22320
Published
Apr 18, 2023
Tracked Since
Feb 18, 2026