CVE-2023-29412
CVE-2023-29412 is a critical-severity vulnerability in Schneider-electric Apc Easy Ups Online Monitoring Software with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (66th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-78
- Affected product: Schneider-electric Apc Easy Ups Online Monitoring Software
- Published:
- Last modified:
Description
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
Frequently asked questions
- What is CVE-2023-29412?
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
- How severe is CVE-2023-29412?
- CVE-2023-29412 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-29412 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (66th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-29412?
- CVE-2023-29412 primarily affects Schneider-electric Apc Easy Ups Online Monitoring Software. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-29412?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2023-29412 published?
- CVE-2023-29412 was published on 2023-04-18 and last updated on 2026-06-17.
References
Affected products (2)
- cpe:2.3:a:schneider-electric:apc_easy_ups_online_monitoring_software:*:*:*:*:*:*:*:*
- cpe:2.3:a:schneider-electric:easy_ups_online_monitoring_software:*:*:*:*:*:*:*:*
More vulnerabilities in Schneider-electric Apc Easy Ups Online Monitoring Software
- CVE-2023-29411 — Critical (CVSS 9.8): A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative…
- CVE-2022-42971 — Critical (CVSS 9.8): A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution…
- CVE-2022-42970 — Critical (CVSS 9.8): A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for…
- CVE-2022-42973 — High (CVSS 7.8): A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local…
- CVE-2022-42972 — High (CVSS 7.8): A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege…
- CVE-2023-29413 — High (CVSS 7.5): A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when…
All CVEs affecting Schneider-electric Apc Easy Ups Online Monitoring Software →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…
- CVE-2026-48362 — Critical (CVSS 10.0): ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…
- CVE-2026-16812 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-6516 — Critical (CVSS 10.0): Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to…
- CVE-2026-46339 — Critical (CVSS 10.0): 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect…
- CVE-2026-59726 — Critical (CVSS 10.0): Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment…