← Back

CVE-2018-7820

nvd nist
Published: Sep 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.

Affected (4)

Ap9630 Firmware
Smart Ups Srt 5kva Firmware
Ap9631 Firmware
Ap9635 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.7.2
Running on/withPlatform Versions
Schneider Electric
Ap9630
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.7.2
Running on/withPlatform Versions
Schneider Electric
Smart Ups Srt 5kva
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.7.2
Running on/withPlatform Versions
Schneider Electric
Ap9631
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 6.7.2
Running on/withPlatform Versions
Schneider Electric
Ap9635
All versions

References (2)

Source: cybersecurity@se.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.