GPU VulnDB

Database/Firmware, BMC & network fabric

APC Easy UPS Online Monitoring Software (Windows and Windows Server): Unrestricted file upload leads to remote code

CVE-2022-42971Firmware, BMC & network fabricSEVD-2022-256-01curated

Impact

Unrestricted file upload leads to remote code execution by dropping a JSP payload. Full control of the host that orchestrates UPS shutdowns across the site - which is the same PHYSICAL outcome as above, plus a persistent Windows foothold sitting on the facility network.

Who can reach it

Unauthenticated network access to the monitoring server's web component.

What to do

Software upgrade per SEVD-2022-256-01, then treat the host as potentially compromised and rebuild it rather than patching in place if it was ever internet-reachable. Verify what the box could reach - it usually holds credentials for every UPS and every managed host it can shut down.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.