Apc records
14 published records for vendor apc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 7.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-0311No exploit | American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUapc · ap9606 | Critical10.0 | — | 2.5% | Nov 23, 2004 |
36Monitor | CVE-2020-7526No exploit | Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code exapc · powerchute · CWE-20 | High8.8 | — | 2.3% | Aug 31, 2020 |
36Monitor | CVE-2000-1242No exploit | The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain sapc · powerchute | Critical9.0 | — | 1.6% | Dec 31, 2000 |
29Monitor | CVE-2007-6226No exploit | The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remotapc · oas · CWE-287 | High7.1 | — | 1.8% | Dec 4, 2007 |
28Monitor | CVE-2003-0099No exploit | Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbapc · apcupsd | High7.2 | — | 0.6% | Mar 3, 2003 |
27Monitor | CVE-2009-1797No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched apc · network management card · CWE-352 | Medium6.8 | — | 0.7% | Dec 28, 2009 |
21Monitor | CVE-2001-0564Proof of concept | APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial ofapc · ap9606 | Medium5.0 | — | 3.2% | Aug 22, 2001 |
21Monitor | CVE-2004-2046No exploit | Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown apc · powerchute | Medium5.0 | — | 2.6% | Dec 31, 2004 |
20Monitor | CVE-2005-4326No exploit | The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), apc · powerchute network shutdown | Medium5.0 | — | 1.5% | Dec 17, 2005 |
20Monitor | CVE-2002-1924No exploit | PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackapc · powerchute | Medium5.0 | — | 1.4% | Dec 31, 2002 |
18Monitor | CVE-2009-1798Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDapc · network management card · CWE-79 | Medium4.3 | — | 2.0% | Dec 28, 2009 |
17Monitor | CVE-2009-4406No exploit | Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3 apc · ap7932 b2 firmware · CWE-79 | Medium4.3 | — | 1.1% | Dec 23, 2009 |
17Monitor | CVE-2011-4263No exploit | Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbiapc · powerchute · CWE-79 | Medium4.3 | — | 0.8% | Dec 7, 2011 |
8Monitor | CVE-2001-0040Proof of concept | APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying apc · apcupsd | Low2.1 | — | 0.9% | Feb 16, 2001 |
- CVE-2004-031141Plan
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanU
CriticalCVSS 10.0No exploitEPSS 2%apc · ap9606Nov 23, 2004
- CVE-2020-752636Monitor
Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code ex
HighCVSS 8.8No exploitEPSS 2%apc · powerchuteAug 31, 2020
- CVE-2000-124236Monitor
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain s
CriticalCVSS 9.0No exploitEPSS 2%apc · powerchuteDec 31, 2000
- CVE-2007-622629Monitor
The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remot
HighCVSS 7.1No exploitEPSS 2%apc · oasDec 4, 2007
- CVE-2003-009928Monitor
Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arb
HighCVSS 7.2No exploitEPSS 1%apc · apcupsdMar 3, 2003
- CVE-2009-179727Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched
MediumCVSS 6.8No exploitEPSS 1%apc · network management cardDec 28, 2009
- CVE-2001-056421Monitor
APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of
MediumCVSS 5.0Proof of conceptEPSS 3%apc · ap9606Aug 22, 2001
- CVE-2004-204621Monitor
Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown
MediumCVSS 5.0No exploitEPSS 3%apc · powerchuteDec 31, 2004
- CVE-2005-432620Monitor
The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded),
MediumCVSS 5.0No exploitEPSS 1%apc · powerchute network shutdownDec 17, 2005
- CVE-2002-192420Monitor
PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attack
MediumCVSS 5.0No exploitEPSS 1%apc · powerchuteDec 31, 2002
- CVE-2009-179818Monitor
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PD
MediumCVSS 4.3Proof of conceptEPSS 2%apc · network management cardDec 28, 2009
- CVE-2009-440617Monitor
Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3
MediumCVSS 4.3No exploitEPSS 1%apc · ap7932 b2 firmwareDec 23, 2009
- CVE-2011-426317Monitor
Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbi
MediumCVSS 4.3No exploitEPSS 1%apc · powerchuteDec 7, 2011
- CVE-2001-00408Monitor
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying
LowCVSS 2.1Proof of conceptEPSS 1%apc · apcupsdFeb 16, 2001