CVE-2022-0715
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID=1020: UPS 10.4 and prior / SRT Series ID=1021: UPS 12.2 and prior / SRT Series ID=1001/1013: UPS 05.1 and prior / SRT Series ID=1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)
Affected (33)
Products: Schneider Electric: Smt Series 1015 Ups Firmware, Smc Series 1018 Ups Firmware, Smtl Series 1026 Ups Firmware, Scl Series 1029 Ups Firmware, Scl Series 1037 Ups Firmware, Smx Series 1031 Ups Firmware, Smt Series 18 Ups Firmware, Smt Series 1040 Ups Firmware, Smt Series 1031 Ups Firmware, Smc Series 1005 Ups Firmware, Smc Series 1007 Ups Firmware, Smc Series 1041 Ups Firmware, Scl Series 1030 Ups Firmware, Scl Series 1036 Ups Firmware, Smx Series 20 Ups Firmware, Smx Series 23 Ups Firmware, Srt Series 1010 Ups Firmware, Srt Series 1019 Ups Firmware, Srt Series 1025 Ups Firmware, Srt Series 1020 Ups Firmware, Srt Series 1021 Ups Firmware, Srt Series 1001 Ups Firmware, Srt Series 1013 Ups Firmware, Srt Series 1002 Ups Firmware, Srt Series 1014 Ups Firmware, Srtl1000rmxli Firmware, Srtl1000rmxli Nc Firmware, Srtl1500rmxli Nc Firmware, Srtl1500rmxli Firmware, Srtl2200rmxli Firmware, Srtl2200rmxli Nc Firmware, Srtl3000rmxli Nc Firmware, Srtl3000rmxli Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 04.5 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smt Series 1015 Ups | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 04.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smc Series 1018 Ups | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 02.9 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smtl Series 1026 Ups | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 02.5 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Scl Series 1029 Ups | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 03.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Scl Series 1037 Ups | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 03.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smx Series 1031 Ups | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 09.8 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smt Series 18 Ups | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smt Series 1040 Ups | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 03.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smt Series 1031 Ups | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 14.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smc Series 1005 Ups | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 11.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smc Series 1007 Ups | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smc Series 1041 Ups | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 02.5 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Scl Series 1030 Ups | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 02.5 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Scl Series 1036 Ups | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smx Series 20 Ups | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 07.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Smx Series 23 Ups | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 08.3 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1010 Ups | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 08.3 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1019 Ups | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 08.3 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1025 Ups | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.4 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1020 Ups | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1021 Ups | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 05.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1001 Ups | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 05.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1013 Ups | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to a05.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1002 Ups | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to a05.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srt Series 1014 Ups | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl1000rmxli | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl1000rmxli Nc | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl1500rmxli Nc | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl1500rmxli | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl2200rmxli | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl2200rmxli Nc | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl3000rmxli Nc | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 01.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Srtl3000rmxli | All versions |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
References (2)
Source: cybersecurity@se.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.