← Back

CVE-2022-42971

nvd nist
Published: Feb 1, 2023Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Affected (4)

Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.5-ga-01-22320
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.5-gs-01-22320
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.5-ga
Configuration D
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Before 2.5-gs
Running on/withPlatform Versions
Microsoft
Windows 10
All versions
Microsoft
Windows 11
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows Server 2016
All versions
Microsoft
Windows Server 2019
All versions
Microsoft
Windows Server 2022
All versions

Timeline

No history available yet.