目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1325

100%

CVE-2022-0715— 多款Schneider Electric产品数据伪造问题漏洞

AI 预测 7.5 利用难度: 困难 EPSS 5.80% · P92

影响版本矩阵 10

厂商产品版本范围状态
Schneider ElectricAPC Smart-UPSSMT Seriesaffected
SMC Seriesaffected
SCL Seriesaffected
SMX Seriesaffected
SRT Seriesaffected
Schneider ElectricSmartConnectSMT Seriesaffected
SMC Seriesaffected
SMTL Seriesaffected
SCL Seriesaffected
SMX Seriesaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2022-0715 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID=1020: UPS 10.4 and prior / SRT Series ID=1021: UPS 12.2 and prior / SRT Series ID=1001/1013: UPS 05.1 and prior / SRT Series ID=1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
认证机制不恰当
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
多款Schneider Electric产品数据伪造问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Schneider Electric APC Smart-UPS SMC Series等都是法国施耐德电气(Schneider Electric)公司的产品。Schneider Electric APC Smart-UPS SMC Series是一款适用于单台服务器、低功耗网络和销售点 (POS) 设备的入门级 UPS。Schneider Electric APC Smart-UPS SMT Series是一款服务器、销售点、路由器、交换机、集线器和其他网络设备的线路交互式电源保护。Schneider E
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
Schneider ElectricAPC Smart-UPS SMT Series -
Schneider ElectricSmartConnect SMT Series -

二、漏洞 CVE-2022-0715 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2022-0715 的情报信息

登录查看更多情报信息。

CVE-2022-0715 其他参考 (1)

同批安全公告 · Schneider Electric · 2022-03-09 · 共 6 条

CVE-2021-227838.8 HIGHSchneider Electric Ritto Wiser Door 安全漏洞
CVE-2022-243225.3 MEDIUMSchneider Electric EcoStruxure Control Experta 缓冲区错误漏洞
CVE-2022-243235.3 MEDIUMSchneider Electric EcoStruxure Control Expert和Schneider Electric EcoStruxure Process Exper
CVE-2022-22805Schneider Electric 多款产品缓冲区错误漏洞
CVE-2022-22806Schneider Electric 多款产品授权问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2022-0715

暂无评论


发表评论