Database/Firmware, BMC & network fabric

APC Easy UPS On-Line Software (SFAPV9601) FileUploadServlet: Path traversal in a file upload servlet allows writing
Impact
Path traversal in a file upload servlet allows writing an executable anywhere on the host, giving code execution on the machine that manages UPS shutdown across the site. Same PHYSICAL end state as the newer Easy UPS bugs - an attacker gains the ability to command an orderly power-down of everything the software manages.
Who can reach it
Unauthenticated network access to the software's web servlet.
What to do
Upgrade past v2.0. Server-side upgrade, cheap. If the host was exposed, rebuild rather than patch - and rotate every UPS and host credential it stored.
References
Related entries
- Arista EOS (eAPI certificate auth): Certificate-based eAPI authentication skips credential re-evaluationCVE-2021-28503 · Arista EOS (eAPI certificate auth)Critical
- HPE iLO Amplifier Pack (unauthenticated directory traversal): Unauthenticated directory traversal on the iLO AmplifierCVE-2021-29212 · HPE iLO Amplifier Pack (unauthenticated directory traversal)Critical
- Insyde InsydeH2O (AtaLegacySmm SMM driver): The SMI handler in the legacy ATA driver does not validate the CommBufferCVE-2021-41842 · Insyde InsydeH2O (AtaLegacySmm SMM driver)Critical
- ArubaOS-Switch (HPE Aruba wired switches): Remote arbitrary code execution on ArubaOS-Switch devices, affectingCVE-2022-23676 · ArubaOS-Switch (HPE Aruba wired switches)Critical
- coreboot 4.13-4.16 (SMM handling on application processors): Arbitrary code execution in System Management ModeCVE-2022-29264 · coreboot 4.13-4.16 (SMM handling on application processors)Critical
- Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flash: The OSCVE-2022-32295 · Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flashCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.