Critical severity9.8NVD Advisory· Published Apr 18, 2023· Updated Jun 17, 2026
CVE-2023-29411
CVE-2023-29411
Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
Affected products
5- cpe:2.3:a:schneider-electric:apc_easy_ups_online_monitoring_software:*:*:*:*:*:*:*:*Range: <=2.5-ga-01-22320
cpe:2.3:a:schneider-electric:easy_ups_online_monitoring_software:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:schneider-electric:easy_ups_online_monitoring_software:*:*:*:*:*:*:*:*range: <=2.5-gs-01-22320
- (no CPE)range: V2.5-GA-01-22320
- (no CPE)range: V2.5-GS-01-22320
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdMitigationPatchVendor Advisory
News mentions
0No linked articles in our index yet.