CVE-2022-42970 PUBLISHED CVSS 9.800000190734863 CRITICAL

A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

EPSS 0.53% · 67.0th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.53%
67.0th percentile

Affected Products

VendorProductVersions
schneider-electricapc_easy_ups_online_monitoring_software0, 0
schneider-electriceasy_ups_online_monitoring_software0, 0
Schneider ElectricSchneider Electric Easy UPS Online Monitoring SoftwareWindows 7, 10, 11 Windows Server 2016, 2019, 2022, Windows 11, Windows Server 2019, 2022
Schneider ElectricAPC Easy UPS Online Monitoring Software(Windows 11, Windows Server 2019, 2022, Windows 7, 10, 11 Windows Server 2016, 2019, 2022

Timeline

References

Open in Interactive Console →