The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric APC Easy UPS On-Line Software V2.0 and earlier
- Summary
- A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability occurs when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories.
- Remediation
- The vulnerabilities are fixed in V2.1 which is available for download below: https://www.se.com/ww/en/product/SFAPV9601/apc-easy-ups-online-software/
