ZeroHour

CVE-2023-29411

CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
Modified
Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.

Vendors
schneider-electric
Products
apc easy ups online monitoring software, easy ups online monitoring software
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.