CVE-2022-42972 PUBLISHED CVSS 7.800000190734863 HIGH

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

EPSS 0.12% · 30.3th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
30.3th percentile

Affected Products

VendorProductVersions
schneider-electriceasy_ups_online_monitoring_software0, 0
schneider-electricapc_easy_ups_online_monitoring_software0, 0
Schneider ElectricSchneider Electric Easy UPS Online Monitoring SoftwareWindows 7, 10, 11 Windows Server 2016, 2019, 2022, Windows 11, Windows Server 2019, 2022
Schneider ElectricAPC Easy UPS Online Monitoring SoftwareWindows 7, 10, 11 Windows Server 2016, 2019, 2022, (Windows 11, Windows Server 2019, 2022

Timeline

References

Open in Interactive Console →