Unknown
CVE-2022-0715
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2022-0715
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior / SMT Series ID=1040: UPS 01.2 and prior / SMT Series ID=1031: UPS 03.1 and prior), SMC Series (SMC Series ID=1005: UPS 14.1 and prior / SMC Series ID=1007: UPS 11.0 and prior / SMC Series ID=1041: UPS 01.1 and prior), SCL Series (SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior), SMX Series (SMX Series ID=20: UPS 10.2 and prior / SMX Series ID=23: UPS 07.0 and prior), SRT Series (SRT Series ID=1010/1019/1025: UPS 08.3 and prior / SRT Series ID=1024: UPS 01.0 and prior / SRT Series ID=1020: UPS 10.4 and prior / SRT Series ID=1021: UPS 12.2 and prior / SRT Series ID=1001/1013: UPS 05.1 and prior / SRT Series ID=1002/1014: UPSa05.2 and prior), APC SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- scl series 1029 ups firmware,
- scl series 1030 ups firmware,
- scl series 1036 ups firmware,
- scl series 1037 ups firmware,
- smc series 1005 ups firmware,
- smc series 1007 ups firmware,
- smc series 1018 ups firmware,
- smc series 1041 ups firmware,
- smt series 1015 ups firmware,
- smt series 1031 ups firmware,
- smt series 1040 ups firmware,
- smt series 18 ups firmware,
- smtl series 1026 ups firmware,
- smx series 1031 ups firmware,
- smx series 20 ups firmware,
- smx series 23 ups firmware,
- srt series 1001 ups firmware,
- srt series 1002 ups firmware,
- srt series 1010 ups firmware,
- srt series 1013 ups firmware,
- srt series 1014 ups firmware,
- srt series 1019 ups firmware,
- srt series 1020 ups firmware,
- srt series 1021 ups firmware,
- srt series 1025 ups firmware,
- srtl1000rmxli firmware,
- srtl1000rmxli-nc firmware,
- srtl1500rmxli firmware,
- srtl1500rmxli-nc firmware,
- srtl2200rmxli firmware,
- srtl2200rmxli-nc firmware,
- srtl3000rmxli firmware,
- srtl3000rmxli-nc firmware
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: