Записи Apc
14 опубликованных записей вендора apc.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 7,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2004-0311Эксплойта нет | American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUapc · ap9606 | Критическая10,0 | — | 2,5 % | 23 нояб. 2004 г. |
36Наблюдать | CVE-2020-7526Эксплойта нет | Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code exapc · powerchute · CWE-20 | Высокая8,8 | — | 2,3 % | 31 авг. 2020 г. |
36Наблюдать | CVE-2000-1242Эксплойта нет | The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain sapc · powerchute | Критическая9,0 | — | 1,6 % | 31 дек. 2000 г. |
29Наблюдать | CVE-2007-6226Эксплойта нет | The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remotapc · oas · CWE-287 | Высокая7,1 | — | 1,8 % | 4 дек. 2007 г. |
28Наблюдать | CVE-2003-0099Эксплойта нет | Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbapc · apcupsd | Высокая7,2 | — | 0,6 % | 3 мар. 2003 г. |
27Наблюдать | CVE-2009-1797Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched apc · network management card · CWE-352 | Средняя6,8 | — | 0,7 % | 28 дек. 2009 г. |
21Наблюдать | CVE-2001-0564Proof of concept | APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial ofapc · ap9606 | Средняя5,0 | — | 3,2 % | 22 авг. 2001 г. |
21Наблюдать | CVE-2004-2046Эксплойта нет | Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown apc · powerchute | Средняя5,0 | — | 2,6 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2005-4326Эксплойта нет | The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), apc · powerchute network shutdown | Средняя5,0 | — | 1,5 % | 17 дек. 2005 г. |
20Наблюдать | CVE-2002-1924Эксплойта нет | PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackapc · powerchute | Средняя5,0 | — | 1,4 % | 31 дек. 2002 г. |
18Наблюдать | CVE-2009-1798Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDapc · network management card · CWE-79 | Средняя4,3 | — | 2,0 % | 28 дек. 2009 г. |
17Наблюдать | CVE-2009-4406Эксплойта нет | Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3 apc · ap7932 b2 firmware · CWE-79 | Средняя4,3 | — | 1,1 % | 23 дек. 2009 г. |
17Наблюдать | CVE-2011-4263Эксплойта нет | Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbiapc · powerchute · CWE-79 | Средняя4,3 | — | 0,8 % | 7 дек. 2011 г. |
8Наблюдать | CVE-2001-0040Proof of concept | APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying apc · apcupsd | Низкая2,1 | — | 0,9 % | 16 февр. 2001 г. |
- CVE-2004-031141В плане
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanU
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %apc · ap960623 нояб. 2004 г.
- CVE-2020-752636Наблюдать
Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code ex
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %apc · powerchute31 авг. 2020 г.
- CVE-2000-124236Наблюдать
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain s
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %apc · powerchute31 дек. 2000 г.
- CVE-2007-622629Наблюдать
The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remot
ВысокаяCVSS 7,1Эксплойта нетEPSS 2 %apc · oas4 дек. 2007 г.
- CVE-2003-009928Наблюдать
Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arb
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %apc · apcupsd3 мар. 2003 г.
- CVE-2009-179727Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched
СредняяCVSS 6,8Эксплойта нетEPSS 1 %apc · network management card28 дек. 2009 г.
- CVE-2001-056421Наблюдать
APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of
СредняяCVSS 5,0Proof of conceptEPSS 3 %apc · ap960622 авг. 2001 г.
- CVE-2004-204621Наблюдать
Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown
СредняяCVSS 5,0Эксплойта нетEPSS 3 %apc · powerchute31 дек. 2004 г.
- CVE-2005-432620Наблюдать
The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded),
СредняяCVSS 5,0Эксплойта нетEPSS 1 %apc · powerchute network shutdown17 дек. 2005 г.
- CVE-2002-192420Наблюдать
PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attack
СредняяCVSS 5,0Эксплойта нетEPSS 1 %apc · powerchute31 дек. 2002 г.
- CVE-2009-179818Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PD
СредняяCVSS 4,3Proof of conceptEPSS 2 %apc · network management card28 дек. 2009 г.
- CVE-2009-440617Наблюдать
Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3
СредняяCVSS 4,3Эксплойта нетEPSS 1 %apc · ap7932 b2 firmware23 дек. 2009 г.
- CVE-2011-426317Наблюдать
Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbi
СредняяCVSS 4,3Эксплойта нетEPSS 1 %apc · powerchute7 дек. 2011 г.
- CVE-2001-00408Наблюдать
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying
НизкаяCVSS 2,1Proof of conceptEPSS 1 %apc · apcupsd16 февр. 2001 г.