Skip to content
Noroxi

Apc records

14 published records for vendor apc.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
7.1%
Median publish → KEV
No record has entered KEV

All records

14 records
  • American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanU

    CriticalCVSS 10.0No exploitEPSS 2%

    apc · ap9606Nov 23, 2004

  • CVE-2020-7526
    36Monitor

    Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code ex

    HighCVSS 8.8No exploitEPSS 2%

    apc · powerchuteAug 31, 2020

  • CVE-2000-1242
    36Monitor

    The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain s

    CriticalCVSS 9.0No exploitEPSS 2%

    apc · powerchuteDec 31, 2000

  • CVE-2007-6226
    29Monitor

    The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remot

    HighCVSS 7.1No exploitEPSS 2%

    apc · oasDec 4, 2007

  • CVE-2003-0099
    28Monitor

    Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arb

    HighCVSS 7.2No exploitEPSS 1%

    apc · apcupsdMar 3, 2003

  • CVE-2009-1797
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched

    MediumCVSS 6.8No exploitEPSS 1%

    apc · network management cardDec 28, 2009

  • CVE-2001-0564
    21Monitor

    APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of

    MediumCVSS 5.0Proof of conceptEPSS 3%

    apc · ap9606Aug 22, 2001

  • CVE-2004-2046
    21Monitor

    Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown

    MediumCVSS 5.0No exploitEPSS 3%

    apc · powerchuteDec 31, 2004

  • CVE-2005-4326
    20Monitor

    The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded),

    MediumCVSS 5.0No exploitEPSS 1%

    apc · powerchute network shutdownDec 17, 2005

  • CVE-2002-1924
    20Monitor

    PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attack

    MediumCVSS 5.0No exploitEPSS 1%

    apc · powerchuteDec 31, 2002

  • CVE-2009-1798
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PD

    MediumCVSS 4.3Proof of conceptEPSS 2%

    apc · network management cardDec 28, 2009

  • CVE-2009-4406
    17Monitor

    Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3

    MediumCVSS 4.3No exploitEPSS 1%

    apc · ap7932 b2 firmwareDec 23, 2009

  • CVE-2011-4263
    17Monitor

    Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbi

    MediumCVSS 4.3No exploitEPSS 1%

    apc · powerchuteDec 7, 2011

  • APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying

    LowCVSS 2.1Proof of conceptEPSS 1%

    apc · apcupsdFeb 16, 2001