CVE Published: 18/04/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: schneider |
Vendor: Schneider Electric |
Product: APC Easy UPS Online Monitoring Software (Windows 10, 11 Windows Server 2016, 2019, 2022) Status : PUBLISHED
CVE-2023-29411 Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H