The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 Windows Server 2016, 2019, 2022) <=2.5-GA
- Schneider Electric APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022) <=2.5-GA-01-22261
- Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 Windows Server 2016, 2019, 2022) <=2.5-GA
- Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022) <=2.5-GA-01-22261
- Summary
- A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
- Remediation
- Version 2.5-GA-01-22320of APC Easy UPS Online Monitoring Software includes a fix for the vulnerabilities impacting Windows 7, 10, 11, and Windows Server 2016, 2019, and 2022 and is available for direct download here: https://download.schneider-electric.com/files?p_Doc_Ref=APC_install_APC_UPS_windows&p_enDocType=Software+-+Release&p_File_Name=installAPCUPS_windows-2.5-GA-01-22320.zip
