VYPR

SmartConnect Family

by Schneider Electric

CVEs (3)

  • CVE-2022-0715CriMar 9, 2022
    risk 0.59cvss 9.1epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior…

  • CVE-2022-22805Mar 9, 2022
    risk 0.01cvss epss 0.08

    A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and…

  • CVE-2022-22806Mar 9, 2022
    risk 0.00cvss epss 0.00

    A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC…