The vulnerabilities include a missing authentication for critical function, unrestricted upload of file with dangerous type, incorrect permission assignment for critical resource, and use of hard-coded credentials.
Successful exploitation of these remotely exploitable vulnerabilities could result in unauthenticated remote code execution, unauthenticated password changes, and escalation of privileges. Rgod working with Trend Micro Zero Day Initiative reported CVE-2022-42970, CVE-2022-42971, and CVE-2022-42973, while Piotr Bazydlo of Trend Micro Zero Day Initiative reported CVE-2022-42972.
The following versions of APC Easy UPS Online, an uninterruptible power supply (UPS) monitoring software, suffer from the vulnerabilities:
- APC Easy UPS Online Version 2.5-GA and prior (Windows 7, 10, 11, Windows Server 2016, 2019, 2022)
- APC Easy UPS Online Version 2.5-GA-01-22261 and prior (Windows 11, Windows Server 2019, 2022)
In one issue, Schneider Electric APC Easy UPS Online versions 2.5-GA and prior are missing authentication for the updatePassword endpoint implemented in the LoginAction.updatePassword method. An unauthenticated user could exploit this vulnerability to modify administrator passwords.
CVE-2022-42970 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 9.8.
In addition, Schneider Electric APC Easy UPS Online versions 2.5-GA and prior deploy the improperly secured UpLoadAction.execute method. An unauthenticated user could use this method to upload a maliciously crafted JSF file to the images directory, which is located in the application web root directory, to enable unauthenticated remote code execution.
CVE-2022-42971 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 9.8.
Also, Schneider Electric APC Easy UPS Online versions 2.5-GA and prior run the Tomcat instance with SYSTEM privileges. “NT AUTHORITY\Authenticated Users” could create new files in the Tomcat web root directory and could create and execute a maliciously crafted JSP file to escalate privileges and execute commands with system privileges.
CVE-2022-42972 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.
In another issue, Schneider Electric APC Easy UPS Online versions 2.5-GA and prior use hard-coded MySQL database credentials. A local unauthorized user with access to the database could use the “select into dumpfile” operation to create arbitrary files, which could be used to execute commands with system privileges.
CVE-2022-42973 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.
The product sees use in multiple industrial sectors, and on a global basis.
No known public exploits specifically target these vulnerabilities. However, an attacker with low skill level could leverage these low complexity vulnerabilities.
Schneider Electric recommends users to update the affected product to the latest version.

