CVE-2022-42973
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5-ga-01-22320 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5-gs-01-22320 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5-ga |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5-gs |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Microsoft Windows 11 | All versions |
Microsoft Windows 7 | All versions |
Microsoft Windows Server 2016 | All versions |
Microsoft Windows Server 2019 | All versions |
Microsoft Windows Server 2022 | All versions |
References (2)
Source: cybersecurity@se.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.