CVE-2022-0715

A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID18: UPS 09.8 and prior / SMT Series ID1040: UPS 01.2 and prior / SMT Series ID1031: UPS 03.1 and prior), SMC Series (SMC Series ID1005: UPS 14.1 and prior / SMC Series ID1007: UPS 11.0 and prior / SMC Series ID1041: UPS 01.1 and prior), SCL Series (SCL Series ID1030: UPS 02.5 and prior / SCL Series ID1036: UPS 02.5 and prior), SMX Series (SMX Series ID20: UPS 10.2 and prior / SMX Series ID23: UPS 07.0 and prior), SRT Series (SRT Series ID1010/1019/1025: UPS 08.3 and prior / SRT Series ID1024: UPS 01.0 and prior / SRT Series ID1020: UPS 10.4 and prior / SRT Series ID1021: UPS 12.2 and prior / SRT Series ID1001/1013: UPS 05.1 and prior / SRT Series ID1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID1015: UPS 04.5 and prior), SMC Series (SMC Series ID1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID1026: UPS 02.9 and prior), SCL Series (SCL Series ID1029: UPS 02.5 and prior / SCL Series ID1030: UPS 02.5 and prior / SCL Series ID1036: UPS 02.5 and prior / SCL Series ID1037: UPS 03.1 and prior), SMX Series (SMX Series ID1031: UPS 03.1 and prior)

Publication date: Thu, 10 Mar 2022 02:15:00 +0000


Cyber News related to CVE-2022-0715

CVE-2022-0715 - A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT ...
11 months ago
CVE-2019-0714 - A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This ...
4 years ago
CVE-2019-0715 - A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This ...
4 years ago
CVE-2019-0717 - A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This ...
4 years ago
CVE-2019-0723 - A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This ...
4 years ago
CVE-2019-0718 - A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This ...
4 years ago
CVE-2020-0792 - An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, ...
2 years ago
CVE-2003-0813 - A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one ...
4 months ago
CVE-2020-0745 - An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, ...
2 years ago
CVE-2020-0715 - An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0745, ...
2 years ago
CVE-2003-0528 - Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than ...
5 years ago
CVE-2003-0715 - Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a ...
5 years ago
CVE-2008-0715 - Buffer overflow in ACDSee Photo Manager 8.1, 9.0, and 10.0 allows user-assisted remote attackers to execute arbitrary code via a malformed XBM file. NOTE: this might be the same as CVE-2007-6009. ...
13 years ago
CVE-2016-0715 - Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote information disclosure. It was found that original mitigation configuration instructions provided as part of ...
4 years ago
CVE-2005-0715 - AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box. ...
15 years ago
CVE-2000-0715 - DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file. ...
15 years ago
CVE-2009-0715 - Unspecified vulnerability in Secure NaviCLI in HP Storage Essentials 6.0.2 through 6.0.4 allows remote authenticated users to obtain "access" or "extended privileges" via unknown vectors. ...
15 years ago
CVE-2001-0715 - Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode. ...
13 years ago
CVE-2013-0715 - The WebCLI component in Wind River VxWorks 5.5 through 6.9 allows remote authenticated users to cause a denial of service (CLI session crash) via a crafted command string. ...
11 years ago
CVE-2015-0715 - SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and ...
8 years ago
CVE-2002-0715 - Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password. ...
7 years ago
CVE-2004-0715 - The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the ...
6 years ago
CVE-2007-0715 - Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file. ...
6 years ago
CVE-2012-0715 - Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified ...
6 years ago
CVE-2011-0715 - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token. Per: ...
6 years ago

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)