Apc kayıtları
apc üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %7,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2004-0311İstismar yok | American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUapc · ap9606 | Kritik10,0 | — | %2,5 | 23 Kas 2004 |
36İzleyin | CVE-2020-7526İstismar yok | Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code exapc · powerchute · CWE-20 | Yüksek8,8 | — | %2,3 | 31 Ağu 2020 |
36İzleyin | CVE-2000-1242İstismar yok | The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain sapc · powerchute | Kritik9,0 | — | %1,6 | 31 Ara 2000 |
29İzleyin | CVE-2007-6226İstismar yok | The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remotapc · oas · CWE-287 | Yüksek7,1 | — | %1,8 | 4 Ara 2007 |
28İzleyin | CVE-2003-0099İstismar yok | Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbapc · apcupsd | Yüksek7,2 | — | %0,6 | 3 Mar 2003 |
27İzleyin | CVE-2009-1797İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched apc · network management card · CWE-352 | Orta6,8 | — | %0,7 | 28 Ara 2009 |
21İzleyin | CVE-2001-0564Kavram kanıtı | APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial ofapc · ap9606 | Orta5,0 | — | %3,2 | 22 Ağu 2001 |
21İzleyin | CVE-2004-2046İstismar yok | Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown apc · powerchute | Orta5,0 | — | %2,6 | 31 Ara 2004 |
20İzleyin | CVE-2005-4326İstismar yok | The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), apc · powerchute network shutdown | Orta5,0 | — | %1,5 | 17 Ara 2005 |
20İzleyin | CVE-2002-1924İstismar yok | PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackapc · powerchute | Orta5,0 | — | %1,4 | 31 Ara 2002 |
18İzleyin | CVE-2009-1798Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDapc · network management card · CWE-79 | Orta4,3 | — | %2,0 | 28 Ara 2009 |
17İzleyin | CVE-2009-4406İstismar yok | Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3 apc · ap7932 b2 firmware · CWE-79 | Orta4,3 | — | %1,1 | 23 Ara 2009 |
17İzleyin | CVE-2011-4263İstismar yok | Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbiapc · powerchute · CWE-79 | Orta4,3 | — | %0,8 | 7 Ara 2011 |
8İzleyin | CVE-2001-0040Kavram kanıtı | APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying apc · apcupsd | Düşük2,1 | — | %0,9 | 16 Şub 2001 |
- CVE-2004-031141Planlayın
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanU
KritikCVSS 10,0İstismar yokEPSS %2apc · ap960623 Kas 2004
- CVE-2020-752636İzleyin
Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code ex
YüksekCVSS 8,8İstismar yokEPSS %2apc · powerchute31 Ağu 2020
- CVE-2000-124236İzleyin
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain s
KritikCVSS 9,0İstismar yokEPSS %2apc · powerchute31 Ara 2000
- CVE-2007-622629İzleyin
The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remot
YüksekCVSS 7,1İstismar yokEPSS %2apc · oas4 Ara 2007
- CVE-2003-009928İzleyin
Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arb
YüksekCVSS 7,2İstismar yokEPSS %1apc · apcupsd3 Mar 2003
- CVE-2009-179727İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched
OrtaCVSS 6,8İstismar yokEPSS %1apc · network management card28 Ara 2009
- CVE-2001-056421İzleyin
APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of
OrtaCVSS 5,0Kavram kanıtıEPSS %3apc · ap960622 Ağu 2001
- CVE-2004-204621İzleyin
Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown
OrtaCVSS 5,0İstismar yokEPSS %3apc · powerchute31 Ara 2004
- CVE-2005-432620İzleyin
The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded),
OrtaCVSS 5,0İstismar yokEPSS %1apc · powerchute network shutdown17 Ara 2005
- CVE-2002-192420İzleyin
PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attack
OrtaCVSS 5,0İstismar yokEPSS %1apc · powerchute31 Ara 2002
- CVE-2009-179818İzleyin
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PD
OrtaCVSS 4,3Kavram kanıtıEPSS %2apc · network management card28 Ara 2009
- CVE-2009-440617İzleyin
Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3
OrtaCVSS 4,3İstismar yokEPSS %1apc · ap7932 b2 firmware23 Ara 2009
- CVE-2011-426317İzleyin
Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbi
OrtaCVSS 4,3İstismar yokEPSS %1apc · powerchute7 Ara 2011
- CVE-2001-00408İzleyin
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying
DüşükCVSS 2,1Kavram kanıtıEPSS %1apc · apcupsd16 Şub 2001